Security Overview
VaultAP is designed from the ground up to protect sensitive accounts-payable data. Security is not an add-on — it is built into every layer of the system, from how data is stored to how AI models interact with your invoices.
Key Security Features
Encryption
All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Bank account details receive additional protection through salted SHA-256 hashing, with only the last four digits stored in plain text.
Authentication
VaultAP uses Clerk-based authentication with email and password login, multi-factor authentication (MFA) support, and secure session management. SSO support is on the roadmap for V2.
Learn more about Authentication
Roles and Permissions
A three-role access control model — Admin, Reviewer, and Viewer — ensures that users only have access to the features they need. Separation of duties is enforced at the system level.
Learn more about Roles & Permissions
Tenant Isolation
Three layers of isolation ensure that data never crosses organizational boundaries: application-level filtering, row-level security in the database, and per-tenant encryption keys.
Learn more about Tenant Isolation
Audit Trail
Every action in VaultAP is recorded in an immutable, hash-chained audit trail. Entries cannot be modified or deleted, and tamper detection alerts you if integrity is ever compromised.
Learn more about the Audit Trail
AI Safety
VaultAP applies strict controls to how AI models interact with your data: data minimization, prompt injection defenses, output validation, and guaranteed fallback behavior. The AI never makes financial decisions — it only explains risk scores.
Compliance
VaultAP is designed for SOC 2 Type I certification readiness and incorporates GDPR considerations including data residency controls, right to deletion, and data portability.
If you have specific security questions not covered in these pages, contact our security team at security@vaultap.com.