Security & Data Protection Measures
Last updated: 2026-10-03
We take the security of financial and personal data seriously. The measures below satisfy our obligations under UK GDPR Article 32 ("appropriate technical and organisational measures").
Tenant isolation & access control
- Multi-tenant isolation: every database query is scoped to an organisation ID; this tenant boundary is enforced at the data-access layer and reviewed on every change.
- Role-based access control (RBAC) at three layers — route gate, server-action gate, and data-layer scope — with roles of admin, manager and staff.
- Least privilege: users and internal services hold only the access they need.
Data storage & encryption
- Primary database (Neon Postgres) hosted in the UK/EU (London), encrypted at rest and in transit (TLS).
- Receipt files stored in a private blob store — never publicly accessible. Files are served only through authenticated, access-gated proxy routes; raw storage URLs are never exposed.
- Encryption in transit: all traffic is served over HTTPS/TLS.
Authentication
- Authentication is delegated to WorkOS AuthKit (hosted sign-in, PKCE).
- Support for organisation roles, invitations, and multi-factor authentication via WorkOS.
- Internal service endpoints (OCR worker, webhooks, cron) are gated by shared secrets and excluded from public routing.
AI / OCR processing
- Receipt images are processed by an AI vision model via the Vercel AI Gateway solely to extract expense fields for human review.
- Every OCR request is sent with a zero-data-retention requirement. Under it, the gateway only routes the request to model providers that have a zero-data-retention agreement with Vercel, and refuses the request if none is available. Under those agreements the provider does not keep receipt data after processing and does not use it to train models. Vercel states that the gateway itself does not retain prompts or outputs.
- The requirement is set in our code on every OCR call, so it does not depend on an account setting being left switched on. These are contractual commitments made by Vercel and the model providers; we rely on them and cannot audit them ourselves.
- Extracted values are presented to a human for review and correction before submission — no solely-automated significant decisions are made.
Operational security
- Infrastructure runs on Vercel (Fluid Compute) and Neon, both of which maintain their own recognised security certifications.
- Application secrets are stored as encrypted environment variables, never in source control.
- Code changes go through review and an automated CI pipeline (typecheck, lint, tests, build) before deployment.
- Audit/log events are captured for security-relevant actions.
Data retention & deletion
- Customer expense data is kept for as long as the customer's workspace is open. When a workspace is closed, its admins have 30 days to download the data or reopen it; after that every expense, receipt file, report and membership is deleted from our live systems. Database history holding it expires within 7 days, and error reports within 90 days.
- Our own billing and tax records are kept for 6 years. See our Privacy Policy for the full schedule.
Incident response
- We maintain a breach-response procedure. Qualifying personal-data breaches are assessed and, where required, reported to the ICO within 72 hours and to affected controllers/individuals without undue delay.
Reporting a vulnerability
If you believe you've found a security issue, please email security@xpense.events. We welcome responsible disclosure and will acknowledge your report promptly.