FinanceInbox
Security
Controls that protect customer evidence and accounting decisions.
- Private, tenant-scoped storage with short-lived signed access links.
- Row-level access policies and role-based permissions for each independent Books workspace.
- Original evidence and issued invoice PDFs retain checksums for auditability and integrity checks.
- Invoice numbering is allocated atomically only after explicit approval; drafts are visibly marked.
- Human approval required before accounting export or Tally posting.
- Durable processing states distinguish waiting, reading, checking, review and failure.
- Database-enforced pilot quotas limit unexpected processing cost.
- Deletion uses a verified request workflow and is blocked by legal hold.
- Provider credentials remain server-side and are rotated without changing customer records.
Never send passwords, OTPs or banking credentials through a support request. Security issues should be reported through the Support page with the affected workspace and time.