SOC 2 Type II
Audited annually by an independent third party
PCI DSS Level 1
Highest tier of card data security compliance
GDPR ready
Data processing agreements for EU customers
ISO 27001
Information security management, certified

Every layer of the platform is built around one rule: least privilege, full visibility.

Encryption in transit and at rest

All data is encrypted with TLS 1.2+ in transit and AES-256 at rest, including card numbers, transaction records, and receipts.

Role-based access control

Every user — from an employee cardholder to a finance admin — only sees the budgets, cards, and transactions their role permits.

Full audit logging

Every policy check, approval, block, and limit change is recorded with a timestamp, actor, and the rule that applied — exportable for any audit.

Single sign-on & SCIM provisioning

Connect your identity provider so access is granted and revoked automatically as employees join or leave.

Real-time fraud monitoring

Card transactions are screened against fraud signals the same way they're screened against budget policy — before authorization.

Data residency options

Enterprise customers can choose where transaction and company data is stored to meet regional requirements.

Regular independent penetration testing

Third-party security firms test the platform at least twice a year; summary reports are available under NDA.

Incident response & disclosure

A documented incident response process with defined customer notification timelines, reviewed as part of our SOC 2 audit.

Need a security questionnaire completed for procurement?

We can share our SOC 2 report, pen test summaries, and a completed questionnaire under NDA.

Contact security team