Your spend data deserves minimal access and auditable evidence.
Spend limits collection, encrypts credentials, and separates every workspace.
Least privilege
Every connector declares read-only capabilities and permissions. Destructive external actions are out of scope.
Encrypted credentials
Tokens are encrypted with AES-256-GCM, versioned for rotation, and never returned to the browser.
Minimized content
No source code, AI prompt, email body, or raw document is retained in logs. Temporary files are purged.
Isolation
The authenticated organization determines the server-side workspace; every business table carries that boundary directly.
Recovery
Migrations are separate from deployment. Backup and recovery procedures must be rehearsed before commercial launch.
Human decision
Recommendations remain advisory. Users confirm reconciliation and retain the final decision.