Security & Cyber Liability Statement
This statement describes how InvoToday protects customer data, how we respond to security incidents, and how responsibility for cyber risk is allocated between InvoToday and its customers. It supplements the Terms of Service, the Privacy Policy, and the Data Processing Addendum; those documents control where they differ. It is a statement of our practices, not a warranty.
1. Architecture and tenant isolation
- InvoToday is a multi-tenant platform. Every business record carries a workspace (tenant) identifier, and application queries are tenant-scoped.
- Tenant isolation is additionally enforced in the database itself with row-level security on tenant tables, so a request scoped to one workspace cannot read or modify another’s rows.
- Production infrastructure runs on Amazon Web Services with host firewalls, restricted administrative access, non-root service containers, and hardened HTTP security headers.
2. Encryption and credentials
- All traffic between your browser and the Service is encrypted with TLS 1.2+.
- Passwords are stored only as one-way salted hashes and are never recoverable in plain text.
- Integration secrets you store with us — e-invoicing certificates, accounting-integration tokens, AI API keys — are encrypted at rest, revealed only through explicit, verified actions, and never displayed again in full after saving.
- Full payment card numbers never touch our systems; payment is handled by Stripe, a PCI-DSS Level 1 provider.
3. Access control and accountability
- Workspace access is governed by role- and permission-based profiles that you administer; seats are named users, and administrators can deactivate users and revoke sessions.
- Optional two-factor authentication (TOTP) is available for user accounts.
- A commit-scoped audit trail records who changed what and when across business records, including changes made by support, API keys, and automated jobs — visible to authorized workspace administrators in the application.
- Our own operational access follows least privilege; support access to a workspace is identified in the audit trail as InvoToday support.
4. Backups and resilience
- Production data is backed up routinely, with encrypted storage and defined rotation.
- Workspace administrators can additionally create and download tenant-level backups and exports at any time; we recommend keeping independent copies of records you are legally required to retain.
- Restore procedures are documented and exercised; restores of customer workspaces are performed on request on a best-efforts basis.
5. Monitoring and vulnerability management
- Application performance and errors are monitored continuously through telemetry, with alerting on anomalies.
- Dependencies and images are updated regularly; security-relevant findings are prioritized ahead of feature work.
- We periodically review the platform against common web-application risks (including the OWASP Top 10) and harden accordingly.
6. Incident response
If we become aware of a security incident affecting customer data, we will:
- Assess and contain — identify scope, stop ongoing exposure, and preserve evidence;
- Notify — inform affected customers without undue delay, targeting within 72 hours of confirming a personal-data breach, with what we know: nature of the incident, data and workspaces affected, and measures taken; we will update as facts develop;
- Remediate — close the vulnerability, rotate affected credentials, and restore integrity from backups where needed; and
- Learn — complete a post-incident review and implement preventive changes.
We will cooperate with customers’ own notification obligations under applicable law, as set out in the Data Processing Addendum. Notification is not an admission of fault.
7. Responsible disclosure
If you believe you have found a vulnerability, email sales@invotoday.com with enough detail to reproduce it. Do not access data that is not yours, degrade the Service, or publicly disclose before we have had a reasonable opportunity to fix the issue. We will acknowledge reports promptly, keep you informed, and will not pursue action against good-faith research conducted within these rules.
8. Your responsibilities
Security of a workspace is shared. Customers are responsible for:
- strong, unique passwords and enabling two-factor authentication for their users;
- assigning permissions on a least-privilege basis and deactivating departed users promptly;
- safeguarding API keys, e-invoicing certificates, and other credentials they supply;
- the accuracy and lawfulness of the data they store; and
- maintaining their own exports of legally required records.
9. Cyber liability and insurance
Responsibility for losses arising from security incidents is allocated by the Terms of Service or, where applicable, a signed Master Services Agreement, including their disclaimers and limitations of liability; nothing in this statement expands those obligations or creates a warranty of absolute security. InvoToday maintains insurance coverage as required by applicable law and as commercially reasonable for a business of its size and risk profile; a summary of relevant coverage is available to customers on written request. Because no provider can eliminate cyber risk, we recommend that customers carry their own cyber liability insurance appropriate to their business, covering incidents that may affect their data wherever it is processed.
10. Questions and changes
Security questionnaires and questions are welcome at sales@invotoday.com. We may update this statement as our practices evolve; the version number and effective date above change with each revision.