Security

Protecting your financial data is not optional — it's foundational.

At ricevuta.ai, security is built into every layer of the platform. Your expense data, receipt images, and company information are protected by enterprise-grade security measures.

Infrastructure

Our infrastructure is hosted on Supabase, which runs on Amazon Web Services (AWS) with data centres in the EU (Zurich, Switzerland — eu-central-2). Switzerland benefits from an EU adequacy decision for data protection, meaning your data receives equivalent protections to data stored within the EU. All infrastructure benefits from AWS's SOC 2, ISO 27001, and ISO 27017 certifications. Database backups are performed automatically and continuously, with point-in-time recovery capabilities.

Encryption

All data is encrypted both in transit and at rest:

  • In transit: All connections use TLS 1.2 or higher. HTTPS is enforced across the entire platform with no exceptions.
  • At rest: Database data and stored files (including receipt images) are encrypted using AES-256 encryption.

Authentication

We use a passwordless authentication model based on one-time email verification codes (OTP). This eliminates the risk of password-related attacks such as credential stuffing, brute force, and password reuse. Each OTP expires after a short period and can only be used once.

Data Isolation

Multi-tenant data isolation is enforced at the database level using Row-Level Security (RLS) policies. Every database query is automatically filtered by company, making it technically impossible for one company to access another company's data — even in the event of an application-level bug.

Receipt Image Processing

When you use the AI extraction feature, your receipt image is sent to Google Gemini for processing via their API. Google processes the image in memory and does not retain, store, or cache it after the extraction is complete. The extracted data is returned to our servers and stored in your company's workspace. We have explicitly configured our API integration so that your data is not used for training, improving, or fine-tuning Google's AI models. This is enforced through Google's API data governance controls. We do not use your receipt images for any purpose other than extracting expense data for your immediate use.

Access Controls

  • Admin and user roles ensure that only authorised personnel can approve expenses, manage team members, and export data.
  • Users can only access their own expense data. Admins can access all data within their company workspace.
  • All access to production systems is restricted, logged, and reviewed.

Secure Development

  • Our codebase is hosted on private repositories.
  • We follow secure coding practices and regularly update dependencies to patch known vulnerabilities.
  • Third-party services are selected based on their security certifications and data handling practices.

Incident Response

In the event of a data breach, we will:

  1. Investigate and contain the incident within 24 hours.
  2. Notify affected customers within 72 hours as required by GDPR.
  3. Report to the relevant supervisory authority (ICO for UK, Garante for Italy) within 72 hours.
  4. Provide a detailed incident report and remediation plan.

Compliance

  • GDPR: We comply with the General Data Protection Regulation for EU data subjects.
  • UK GDPR: We comply with the UK implementation of GDPR.
  • Data Processing Agreements: We maintain DPAs with all third-party sub-processors.

Responsible Disclosure

If you discover a security vulnerability in ricevuta.ai, please report it responsibly to enrico@ricevuta.ai. We will acknowledge your report within 48 hours and work to resolve the issue promptly. We do not pursue legal action against good-faith security researchers.

Questions

For security-related questions, contact us at enrico@ricevuta.ai.