01/Security & data handling
We touch your invoices, ERP, and carrier data. Here's how we treat it.
Scoped, least-privilege access
We work with read-only or narrowly scoped access wherever the workflow allows. We ask for exactly what the system needs and nothing more.
Your data is yours
We never train models on your data. It is processed to run your systems, not to improve a product we sell to someone else.
NDA by default
Every engagement runs under a mutual NDA from the first audit conversation onward.
Deletion on exit
When an engagement ends, we delete the data and revoke access. You get a confirmation.
US-based processing
Data is processed and stored in US-based infrastructure. We document every subprocessor involved.