Security

Last updated: August 25, 2026

This page is written for the person doing due diligence — a finance lead, an accountant, or a developer connecting their own tools. It says plainly what Invco stores and how that data is protected.

1. Credentials we hold on your behalf

The most sensitive thing Invco holds for you is the SMTP/IMAP password that lets it send and read mail from your own address, along with any third-party API key you choose to connect.

These are encrypted at rest with AES-256-GCM using a key held outside the database, so a copy of the database alone does not yield them. They are decrypted only in memory, only at the moment they are used, and they are never rendered back to the browser — once saved, a key can be replaced but not read out of the interface.

2. Isolation between customers

Every company is a separate workspace, and every query Invco runs is scoped to the workspace of the signed-in account. A record belonging to another customer is not filtered out of your results after the fact — it is never in scope to begin with, so an id guessed or copied from elsewhere returns a plain 'not found'.

Where you invite someone into a workspace — a colleague, or a client given sight of one area — their access is scoped by explicit permissions, and access to anything outside the area they were granted is refused at a single shared checkpoint rather than page by page.

3. Accounts and access

  • Passwords are stored only as salted bcrypt hashes; we cannot read yours, and neither can anyone who obtains the database.
  • Optional two-factor authentication (TOTP) on your login.
  • Email verification is required before an account can be used.
  • Sign-in attempts and other sensitive endpoints are rate-limited to blunt credential-stuffing.
  • AI assistants connect with a per-user API key that is scoped to your workspace alone and can be revoked in one click.
  • Administrative access to production is limited to Invco's founder and is not shared.

4. Data in transit and at rest

All traffic to invco.pro is served over HTTPS (TLS 1.2+), with HTTP redirected. Connections between the application and the database are TLS-encrypted, and the database's underlying storage is encrypted at rest.

Invco runs on Vercel (application) and Supabase (PostgreSQL database and file storage), with the primary database and stored files in AWS's us-east-1 region in the United States. Static assets are served from Vercel's global edge network.

5. Logging and monitoring

Application and request logs are retained by our hosting providers and are used for debugging and abuse investigation. Inbound webhooks are recorded with an idempotency key so a replayed or duplicated notification cannot double-apply.

6. Sub-processors

Invco relies on a small number of providers to operate. Each processes data only to provide its service to us. The current list is published in our Privacy Policy and Data Processing Agreement, and includes Vercel (hosting), Supabase (database and file storage), SumUp (payments, as an independent controller), your own email provider, and Google Analytics (usage measurement, only after cookie consent).

7. Incident response

If we become aware of a breach affecting your personal data, we will investigate immediately, contain it, and notify affected customers without undue delay — and, where the law requires it, notify the relevant supervisory authority within 72 hours of becoming aware. Reach us at security@invco.pro for anything security-related.

8. Responsible disclosure

If you believe you have found a vulnerability, please email security@invco.pro with enough detail to reproduce it. We ask that you give us a reasonable opportunity to fix the issue before disclosing it publicly, and that you avoid accessing, modifying, or deleting data belonging to other customers while testing. We will acknowledge your report, keep you updated, and credit you if you would like us to. We will not pursue legal action against researchers who act in good faith under these terms.

9. What we don't claim

Invco is a small, independent product and we would rather be precise than impressive. We do not currently hold SOC 2, ISO 27001, or PCI-DSS Level 1 certification, and we will not imply otherwise. What is described on this page is what is actually implemented; if you need something specific for your own compliance process, ask us and we will tell you honestly whether we have it.

Questions about this policy? Email us at support@invco.pro or message us on WhatsApp.