Set team permissions
Roles and permissions define who can read, create, edit or perform other invoice actions. Accountant access is managed separately.
Set invoice permissions, add two-step verification and work with your accountant through authorized access.
Ask about security →Roles and permissions define who can read, create, edit or perform other invoice actions. Accountant access is managed separately.
Enable two-step verification with an authenticator app and keep your recovery codes safe. Users choose whether to enable it.
Browser access is restricted by company. An accountant needs authorization to work with a client company.
Use the product’s export and backup options. Before closing an account, check what you need to retain and ask about financial history.
Choose roles and permissions to match each person’s work. Check the active company before working with a client’s data.
Scanning uses an external provider, Claude. Review the document and extracted fields before saving.
When you use fiscalization, the fiscal key and pending submissions may be stored on your device. Restrict access to it and keep recovery codes somewhere safe.
Server connections use HTTPS/TLS. Postgres RLS restricts browser-role data by company; privileged server services (service_role) bypass RLS. AES-GCM applies only to fields where encryption is configured.
These controls do not constitute a promise that all stored data is encrypted. Ask about the hosting region and retention periods before use.
We have not published ISO 27001, PCI-DSS or ATK certificates. Card payments depend on provider activation; fiscalization requires SEF setup and approval.
Account closure and deletion of financial history are different actions. Contact us about personal-data requests, retention terms and the data processing agreement.
Technical monitoring filters some sensitive fields, but does not guarantee removal of all personal data. When reporting an issue, describe the steps without sending passwords or card details.
Guaranteed incident-response times and certification reports have not been published.
Tell us your access, retention or privacy requirements. Clarify the terms before bringing your business data.