Security

Built for sensitive AP data

Tixvera asks you to upload invoices, tickets, rate sheets, and vendor pricing. Here is how that data is handled.

Your data stays private to your workspace

Invoices, tickets, rate sheets, and vendor pricing are scoped to your organization. Access is controlled by row-level security and is never visible to other customers.

How your data is protected

Files upload to encrypted storage (Supabase). Extraction and reconciliation run in isolated API workers. Results stay in your workspace. We do not use your vendor pricing to train models or share it across customers.

Role-based access

Owners, admins, controllers, and members get different permission levels. Sensitive actions — approvals, billing, exports — require appropriate roles and are logged.

We do not share or sell your data

We never share or sell vendor pricing or invoice data. Your files are used only to generate your audit and the results you ask for.

Security practices & SOC 2

Security practices are documented on this page. SOC 2 Type II certification is in progress. We are happy to walk through our controls on a call before you upload sensitive AP data.

You can delete your data

Delete uploaded files from your workspace at any time, or request full workspace deletion by email. Free-audit files are retained for 30 days after your last activity unless you delete them sooner.

Subprocessors

We use Supabase (database, auth, storage), Vercel (web hosting), Railway (API hosting), Stripe (billing when enabled), and Sentry (error monitoring). Each processes data only to provide the service.

Security questions?

Sam Carter, Founder, Tixvera sam@tixvera.com

Tixvera flags potential discrepancies for review.

Results are not legal, accounting, or financial advice.

You are responsible for confirming discrepancies before disputing or withholding payment.

Savings are not guaranteed.

See also our Privacy Policy and Terms of Service.