Security & privacy

Your clients' invoices are their business.

Accounting firms are trusted with everything a company buys. Here is how Invoreg keeps that trust, in plain language. Ask us for the detailed version during your demo.

Request the security pack

Where processing happens

Documents are processed on Invoreg infrastructure located in the European Union. Invoice content is processed and stored in EU regions only. We do not train models on your documents.

Access control

Role-based permissions down to individual features — contracts, bank operations, payroll — with super-admin controls for the firm. Every user action on a document is logged with who, what, and the before/after value.

Client separation

Each client company is a separate organisation with its own mailbox, approvers, labels and coding. Users only see the organisations they are assigned to.

Retention and deletion

Deleted documents stay recoverable for the period you set, then are removed. Export everything at any time.

Agreements

GDPR data processing agreement on request. Sub-processors listed on request. Security questionnaire answered within five working days.

Integrations

Your accounting software is connected through OAuth with the minimum scopes needed to read master data and post bills. Tokens are stored encrypted and can be revoked from the accounting software at any time.

Last reviewed September 2026.

Security questions

Questions accountants ask

In the European Union. Invoreg processes and stores documents on infrastructure located in the EU; invoice content is processed and stored in EU regions only. We sign a GDPR data processing agreement with every firm and share the list of sub-processors, with their roles and locations, on request.

Yes, in transit. Every connection to Invoreg and from Invoreg to your accounting software runs over HTTPS with TLS. Access tokens are stored encrypted, the connection uses OAuth with the minimum scopes needed, and your firm can revoke Invoreg's access from the accounting software at any time.

For as long as your firm keeps them. Deleted documents stay recoverable for the retention period you set and are then removed permanently. You can export everything at any time, and at the end of the contract data is deleted as set out in the data processing agreement.

No. Invoreg does not use your documents or your clients' data to train AI models. Documents are processed only to read, check and register invoices for your firm, under the data processing agreement we sign with you, and every action on a document is logged.

A short list of infrastructure and service providers, each bound by a data processing agreement. We share the current list, with every provider's role and processing location, on request and before you sign. Ask during your demo or email hello@invoreg.com and we reply within five working days.