How your data is handled

Data handling

How your data is handled

Plainly, and without overstating it. Where something is not true yet, it is written here rather than left for you to assume.

The guarantee that matters

A language model reads invoice documents. It never decides anything. Every verdict is produced by deterministic code with no model involvement, and every figure is cited to the page it came from — which is why a verdict can be reproduced and checked rather than trusted.

Your payment history

No model ever sees it. The Payment Integrity Review is arithmetic and set comparison performed entirely by our own code. Nothing from your export is sent to Anthropic or to any other external service.

  1. You upload a CSV or XLSX export of paid invoices. It is parsed in memory.
  2. The vendor, invoice number, amount, dates and any entity or remit-to values are stored, so later verifications can be checked against them. That storage is the point: without it, "have we paid this before?" has no answer.
  3. The uploaded file itself is not retained — only the payment rows read from it.
  4. Findings are stored with their evidence and with any decision you record against them.

You can delete all of it at any time, from the button at the foot of the payment history page. That removes every payment, finding, decision and the ledger the Verification Desk checks against.

Invoice documents

The built-in sample invoice is different: its read was performed once by a real model and recorded, so demonstrating the product costs nothing and returns the same answer every time. The interface says which model read it and when. Anything you upload is read live.

  1. You upload a PDF. It is written to a temporary working location for the length of the verification.
  2. Its text is read by Claude (Anthropic), acting as a data subprocessor under a no-training agreement — your document is not used to train any model.
  3. The deterministic checks — arithmetic, tax, duplicate against your imported history, policy, and purchase-order matching when connected — run in our own code.
  4. You receive the verification, the evidence anchors, and the recommendation. The document is purged afterwards.

What leaves your environment

The contents of an invoice document are sent to Anthropic's API to be read. We are not a "your data never leaves" product and will not claim to be. What is true: the read is under a no-training agreement, the document is purged after the verification, and your payment history never leaves at all — it is never sent anywhere.

Honest limitations

  • This is a pilot build, not a security-reviewed production system. The arrangement is documented with you before any real data is loaded.
  • We have no SOC 2, ISO or other certification, and we do not claim one.
  • Access is one shared phrase per organization, not per-person accounts. Everyone on your team who signs in is indistinguishable in the record, so the name recorded against a decision is the one the person typed. Treat the phrase as you would a shared mailbox password, and tell us if someone leaves.
  • Your organization's data is separated from every other organization's at the database level, and no request can reach another organization's data — the identity comes only from your signed session, never from anything in a link.
  • Sessions expire after twelve hours.
  • Evidence anchoring currently covers page 1 of a document; values on later pages appear in the verification timeline but are not yet boxed on the page.
  • Duplicate detection knows only what you have imported. It cannot see payments made before your export period, and it says so rather than reporting a clean check.

What we say — and what we never say

We can truthfully say

  • The model reads; code decides every verdict.
  • The payment history review involves no model at all.
  • Every figure is page-cited, or cited to a row of your own export.
  • We disclose what we could not check.
  • “Verified, page-cited.”

We never say

  • “Audited” (a regulated term).
  • “100% accurate” or “catches all fraud.”
  • “Fully automated approval” — you decide; we recommend.
  • “Secure / compliant / your data never leaves.”

We have tried to answer the questions a finance team should ask before they are asked. If one is missing, that is the most useful thing you can tell us.

Back to payment history