Security

Finance data security is non-negotiable.

We're an AI layer on your most sensitive numbers. Here's exactly how we protect them — no vague language, no empty certifications.

Technical security controls

Every layer of the Spendaq stack is designed for finance-grade data sensitivity. Your GL structure, vendor history, and transaction amounts are among the most sensitive data your company holds. The controls below reflect that — these aren't aspirational roadmap items, they're operational today.

Encryption

AES-256 at rest, TLS 1.3 in transit. Encryption keys managed per-tenant — never shared across customer accounts. Key rotation on 90-day cycle.

Data Isolation

Customer data is logically isolated in separate database schemas. No multi-tenant data co-mingling. Your transaction history is structurally separated from every other customer's data.

Access Controls

Role-based access control. SSO via SAML 2.0 (Okta, Google Workspace, Azure AD). MFA enforced for all admin actions. Principle of least privilege on all internal service accounts.

Data Retention

Transactional data retained for 36 months by default (configurable per account). You can request deletion at any time. Deletion is irreversible and confirmed via audit log.

Audit Logging

Complete audit trail of every categorization decision, human override, and data access event. Logs are exportable for your own compliance audits or vendor security reviews.

Subprocessors

We publish our full subprocessor list. No undisclosed third-party data sharing. Customer data is never used to train models for other customers. Your GL structure stays yours.

Compliance posture

We're a small, self-funded team. We'll be direct about where we stand on formal certifications and where we're heading — rather than using compliance language that implies credentials we don't yet hold.

SOC 2-aligned controls

We've built our infrastructure and access controls to align with SOC 2 Trust Service Criteria for Security, Availability, and Confidentiality. A formal SOC 2 Type II audit is on our 2026 roadmap. If you have a vendor security questionnaire, send it to [email protected] — we'll complete it within 3 business days.

CCPA / US Privacy

We don't sell, rent, or broker customer financial data. California residents have full rights to data access, correction, and deletion under CCPA. Our privacy practices apply to all customers regardless of state.

PCI-DSS Scope Minimization

Spendaq processes transaction records — not raw payment card numbers. We receive categorized spend data, not card PANs or CVVs. The system is designed to stay out of full PCI scope, reducing your compliance surface area rather than expanding it.

Have a security questionnaire?

We'll complete your vendor security assessment. Send it to [email protected] and we'll respond within 3 business days.

Send us your questionnaire