Trust Center

Built for procurement and IT review.

Security, compliance and governance are part of how the platform works. This page is the starting point for your security team. The full documentation is available under NDA.

Security

Eight controls, in place from the first day.

On every entity and every workflow step. The AI recommends, validates and routes. Final authority on payment and policy exceptions stays with your team.

Role-based access

Granular permissions by role, entity and workflow step. Nobody sees more than their function requires.

Audit trails

Every action across capture, validation, matching and approval is logged: who, what, when and why.

Data protection

Hosted on AWS and Oracle Cloud Infrastructure. Vendor and pricing data is protected from competitive exposure.

Human approval controls

The AI recommends, validates and routes. Final authority on payment and policy exceptions stays with your team.

Compliance and governance

Built around GST and e-invoicing mandates, with structured workflows for internal and external audit.

ERP security

Native integration patterns that respect your existing ERP's access controls, never bypass them.

AI governance

Agent actions are scoped, logged and reviewable. The AI operates within defined boundaries, not open-ended autonomy.

Business continuity

Cloud infrastructure designed for resilience, with defined recovery processes for critical finance operations.

Controls

What your reviewers receive.

Each one is in place from the first day, on every entity and every workflow step. The AI recommends, validates and routes. Final authority on payment and policy exceptions stays with your team.

Detailed documentation is available to prospective and current customers under NDA. Ask for any of it and we send it directly to your reviewer. Request the documentation
Controls · in place8 of 8
Role-based access by role, entity and workflow stepLeast privilege
Audit trail on capture, validation, matching and approvalPerson and time
Encrypted in transit and at rest on AWS and Oracle CloudTLS 1.3 · AES-256
Human approval on payment and policy exceptionsYour policy
GST and e-invoicing compliance with audit workflowsBuilt in
ERP access controls respected, never bypassedScoped credentials
Agent actions scoped, logged and reviewableBounded
Recovery processes for critical finance operationsDefined
Shared with your reviewerOn request
Architecture and data-flow diagrams
Under NDA
Data processing and privacy documentation
Under NDA
Access control and authentication model
Under NDA
Incident response and business continuity plans
Under NDA
Sub-processor and cloud infrastructure list
Under NDA
Before a review

Questions security reviewers ask first.

Short answers here. The long ones, with your IT and procurement team, on the reviewer call.

Contact the security team
Where is our data stored and processed?

On AWS and Oracle Cloud Infrastructure, encrypted in transit and at rest. Regions and the data-processing documentation are part of the NDA pack above.

Can the AI pay an invoice on its own?

No. The AI recommends, validates and routes. Payment and policy exceptions require a human approval where your policy says so, and every approval is logged.

Does InvotecAI need write access to our ERP?

It reads purchase orders and goods receipts and writes approved invoices back through the ERP's standard interfaces, under credentials scoped to those actions. The ERP's own access controls stay in force.

Security review

Talk to us about your security review.

We work directly with your IT and procurement team.