Security & Cyber Liability Statement

This statement describes how InvoToday protects customer data, how we respond to security incidents, and how responsibility for cyber risk is allocated between InvoToday and its customers. It supplements the Terms of Service, the Privacy Policy, and the Data Processing Addendum; those documents control where they differ. It is a statement of our practices, not a warranty.

1. Architecture and tenant isolation

2. Encryption and credentials

3. Access control and accountability

4. Backups and resilience

5. Monitoring and vulnerability management

6. Incident response

If we become aware of a security incident affecting customer data, we will:

  1. Assess and contain — identify scope, stop ongoing exposure, and preserve evidence;
  2. Notify — inform affected customers without undue delay, targeting within 72 hours of confirming a personal-data breach, with what we know: nature of the incident, data and workspaces affected, and measures taken; we will update as facts develop;
  3. Remediate — close the vulnerability, rotate affected credentials, and restore integrity from backups where needed; and
  4. Learn — complete a post-incident review and implement preventive changes.

We will cooperate with customers’ own notification obligations under applicable law, as set out in the Data Processing Addendum. Notification is not an admission of fault.

7. Responsible disclosure

If you believe you have found a vulnerability, email sales@invotoday.com with enough detail to reproduce it. Do not access data that is not yours, degrade the Service, or publicly disclose before we have had a reasonable opportunity to fix the issue. We will acknowledge reports promptly, keep you informed, and will not pursue action against good-faith research conducted within these rules.

8. Your responsibilities

Security of a workspace is shared. Customers are responsible for:

9. Cyber liability and insurance

Responsibility for losses arising from security incidents is allocated by the Terms of Service or, where applicable, a signed Master Services Agreement, including their disclaimers and limitations of liability; nothing in this statement expands those obligations or creates a warranty of absolute security. InvoToday maintains insurance coverage as required by applicable law and as commercially reasonable for a business of its size and risk profile; a summary of relevant coverage is available to customers on written request. Because no provider can eliminate cyber risk, we recommend that customers carry their own cyber liability insurance appropriate to their business, covering incidents that may affect their data wherever it is processed.

10. Questions and changes

Security questionnaires and questions are welcome at sales@invotoday.com. We may update this statement as our practices evolve; the version number and effective date above change with each revision.