Security & Privacy Centre

Your invoices and pricing data stay yours.

Supplier Guard AI is designed for finance, procurement and contracting teams handling commercially sensitive supplier information. Documents are encrypted, tenant-isolated, and accessible only to authorised users within your organisation.

Security

The controls protecting every account.

AES-256 encryption at rest

All invoices, line items and pricing data are encrypted with AES-256 in our cloud database and object storage.

TLS in transit

Every connection between your browser, our servers and AI services uses TLS 1.2+ — including invoice uploads and downloads.

Private document storage

Invoices live in private storage buckets. There is no public URL. Downloads use short-lived, signed URLs scoped to your account.

Role-based access control

Database row-level security enforces tenant isolation on every read and write. Users only see records they own.

Secure cloud infrastructure

Hosted on managed cloud infrastructure with automated backups, isolated networks and continuous patch management.

Continuous monitoring

Automated security scans, audit logging, and time-boxed support access — administrators do not have permanent access to customer data.

Privacy

How we handle the data you trust us with.

You own your data.

You retain full ownership of every invoice, supplier record and pricing baseline you upload.

We never sell your invoices.

Your data is not sold to third parties. Ever.

We never share with third parties.

The only third parties that ever touch your data are the secure processing services we use to run the platform (cloud hosting and AI extraction).

No AI training on your data.

Your invoices and supplier data are never used to train AI models — ours or anyone else's. They are processed only to produce results for you.

Processed only to provide the service.

We use your documents to extract line items, detect discrepancies and generate reports for your account. That's it.

Delete anything, any time.

You can delete individual invoices, suppliers and reports — or your entire account — from your settings. Deletions are permanent.

Built for commercially sensitive data

Secure Document Storage
Encrypted Processing
Private Cloud Infrastructure
Customer Data Ownership
AI Processing Only
No AI Training On Customer Data

Compliance & data rights

UK GDPR aligned

Supplier Guard AI is built with UK GDPR principles in mind: lawful basis, data minimisation, storage limitation and security by design.

Data subject requests

Account holders can export and delete their data directly from their settings. Requests from authorised representatives can be raised by contacting support.

Right to erasure

The Delete Account workflow permanently removes invoices, suppliers, line items, discrepancies, reports and stored files for that account.

No marketing cookies

We only set the cookies required to keep you signed in. No third-party analytics or advertising cookies are used in the app.

Questions about compliance, DPAs or security assessments? Contact support.