SECURITY
How we handle your data.
Invoice PDFs are legal evidence in a certification audit. We treat them accordingly. Here is exactly how the platform protects your data and your clients' data.
DATA LIFECYCLE
Upload
PDF stored encrypted
Process
Extraction + ledger built
Download
Ledger retained forever
90 days
Invoice auto-deleted
AES-256 hardware encryption
All files and reports are encrypted using AES-256 keys managed inside an Oracle Cloud Hardware Security Module. The encryption key never leaves the hardware — all encrypt and decrypt operations happen inside the HSM. Raw key material is never accessible to software, including ours.
Two services. Two vaults. No shared access.
Invoice processing and report generation run in completely separate encrypted vaults with separate keys and separate IAM policies. A security event in one service cannot reach the other. This is architectural isolation — not a policy control.
Your invoices are not kept forever.
Uploaded invoice PDFs are automatically deleted after 90 days — enforced at infrastructure level, not just application logic. Generated audit ledgers and reports are retained permanently in a separate encrypted store and remain available whenever you need them.
No file is ever publicly reachable.
All storage is configured with no public access at infrastructure level. Every file requires authenticated access or a time-limited signed request. There is no URL that exposes your clients' invoice files — access controls are enforced by IAM policy, not application-level checks.
Every infrastructure change is tracked.
The entire platform infrastructure is defined in Terraform and stored in version control. Every change to storage configuration, encryption policy, or access control is tracked, reviewed, and reproducible. There is no manually configured server that can drift from its intended state.
For firms running audits for clients.
Full security architecture documentation, data processing agreements, and retention policy details are available on request for procurement and compliance review. Typically required by larger organisations before approving new tools.
Request security documentation →TRANSPORT SECURITY
zerodocpro.com security headers
Headers verified active. HSTS preload submitted.