eProcureAI / Platform / Security

Security and trust

Your spend data,
handled properly

Procurement data shows exactly what your company buys, from whom, at what price and who approved it. We treat it accordingly.

Bring your reviewer to the demo. We would rather answer early than at contract stage.

Security postureData handling
Why this page exists

Procurement data is more sensitive than people assume

Spend data is a map of how a company operates. What it buys, from whom, at what price, who signs it off and where the thresholds sit.

That combination is genuinely sensitive. It reveals commercial terms your suppliers would rather competitors did not see, internal authority structures, and where the approval gaps are for anyone looking to exploit them.

So the security posture here is not a compliance checkbox exercise. Encryption throughout, access granted by department rather than accumulated per person, and an audit trail nobody can quietly edit after the fact.

Bring your reviewer early

The most common failure in a software evaluation is security review happening at contract stage, when everybody has already decided and any finding becomes an argument rather than a question.

We would rather your reviewer joined the demo and asked the hard questions while there is still time for the answer to matter.

The controls

Five areas, and what each actually means

Encryption

In transit and at rest

With keys managed centrally and rotated. Customer data does not leave the environments we control.

AppliesEverywhere
1
Hosting

US based cloud

Redundancy across availability zones, with restore procedures that are tested rather than documented and assumed.

RestoresTested
2
Access

Least privilege by department

Permissions belong to departments and are inherited, with administrative roles kept separate from transactional ones.

ModelLeast privilege
3
Audit trail

Append only

Every approval, amendment, override, signature and export recorded with the actor, the timestamp and the stated reason. Records cannot be edited afterwards.

EditableNo
4
Testing

Independent

Regular penetration testing by third parties plus continuous vulnerability scanning, with findings tracked to closure.

ByNot us
5
How access works

Three decisions that reduce the attack surface

Permissions belong to departments

Access granted to a department and inherited by its members, rather than copied from another user and accumulating over years.

  • Baseline per department rather than per person
  • Inherited on joining and removed on leaving
  • Overrides visible as overrides
  • No permissions carried from a previous role
Access modelLive
Granted toDepartments
InheritedBy members
On role changeRemoved and reapplied
Orphaned accessNone
Follows the roleNot the person

Single sign on through your provider

Authentication uses your existing identity provider, so there is no parallel password estate and your leaver process continues to apply.

  • Authentication through your identity provider
  • Provisioning and de-provisioning follow your process
  • No separate password list to manage
  • Administrative separation preserved
IdentityLive
AuthenticationYour provider
LeaversYour process
Separate passwordsNone
Admin rolesSeparated
One identityNot two

The audit trail cannot be edited

Records are append only. That is the difference between a log, which describes what a system thinks happened, and evidence, which somebody can rely on.

  • Every action recorded with actor and timestamp
  • Reasons captured on overrides
  • Records cannot be altered after the fact
  • Exportable in full on demand
Audit trailLive
RecordsAppend only
Actor and timeOn everything
ReasonsOn overrides
AlterationNot possible
EvidenceRather than a log
For your reviewer

What they will ask for, and where it comes from

Most of this is available under NDA during evaluation. Ask on the call rather than at contract stage.

AreaWhat we provideWhen
ArchitectureOverview and data flow diagramsUnder NDA during evaluation
Sub processorsCurrent list and what each one touchesUnder NDA during evaluation
Third party testingCurrent attestations and summary findingsUnder NDA during evaluation
Access and identityRole definitions, provisioning and de-provisioning flowsOn request
ResilienceBackup cadence, tested restore procedures, incident responseOn request
Data handlingRetention, deletion, export formatsOn request

If your reviewer needs something not listed here, ask. We would rather find out during evaluation than during contracting.

Data ownership

Six commitments about your data

Yours

It remains yours

We process it to provide the service. Ownership does not transfer at any point.

OwnershipUnchanged
Never sold

Or shared

Not with partners, not in aggregate, not as market data.

SoldNever
Not training data

For other customers

Your spend, contracts and supplier terms are not used to train models serving anybody else.

Used elsewhereNo
Exportable

At any time

In standard formats, not as a favour and not as a retention tactic.

AvailableAny time
Deletable

On request

Honoured under the terms in your agreement rather than negotiated at the time.

HonouredOn request
Documented

Who touches what

The sub processor list is available under NDA rather than being something you have to ask twice for.

AvailableUnder NDA
Who does what

The short version of responsibilities

The split matters because a shared responsibility model only works if both halves are stated plainly.

What you control

Your identity provider, your access model, and who can do what inside your organisation.

The human partLive
Identity providerYours
Department baselinesYou set them
Leaver processYours
Reviewing accessPeriodically, from an export
Your sideConfiguration and people

What we control

Everything underneath, including the parts you would otherwise have to run yourselves.

The automatic partLive
EncryptionIn transit and at rest
Hosting and redundancyUS based
Patching and upgradesNot your responsibility
Independent testingRegular
Audit trailAppend only
Our sideInfrastructure and testing
0in transit and at rest, with managed keys
0hosting with redundancy and tested restores
0audit trail that cannot be edited afterwards
0penetration testing with findings tracked to closure
FAQ

Questions people actually ask

Where is our data hosted?
On US based cloud infrastructure with redundancy across availability zones. Requirements outside the United States can be discussed during evaluation.
Who inside our company can see what?
Access is least privilege and granted by department. Budget owners see their budgets, approvers see their queue, managers see their own team, and administrative roles are kept separate from transactional ones.
Do you use our data to train AI models?
No. Your spend, contracts and supplier terms are not used to train models serving other customers, and that does not change as more capability is added.
Can we export the audit trail?
Yes, in full and on demand. Most teams pull it directly for internal review cycles rather than asking us.
What happens to our data if we leave?
It exports in standard formats and deletion is honoured on request under the terms in your agreement.
Can we see your security documentation?
Yes, under NDA during evaluation. That includes the architecture overview, the sub processor list and current third party attestations.
How do you handle single sign on?
Authentication runs through your existing identity provider, so provisioning and de-provisioning follow your process and there is no parallel password estate.
What happens if there is an incident?
Incident response commitments are documented and shared with the security pack. Ask your reviewer to look at that specifically, because it is the part most worth reading carefully.

Bring your security reviewer to the demo

We would rather answer the hard questions early than discover them at contract stage.

Book your free demo

Related: Access and Permissions