Security
This page describes what the system does today. Where something is a deliberate limit rather than a feature, it says so.
The person who prepares an invoice cannot approve it. The person who records a payment cannot verify it. These are not settings an administrator can quietly switch off to save time - the actions refuse, every time, and the attempt is logged.
Your clients pay into your own bank accounts, printed on your own invoices. We do not hold, route, or touch that money, which means there is no balance of yours for us to lose. The only payment we process is your subscription to us.
Every database read and write filters by your organisation as part of the query itself, rather than fetching a record and then asking whether you should have seen it. A record ID belonging to another company behaves exactly like an ID that does not exist.
Sign-ins, approvals, bank-detail changes, payment records, exports. Who did what, when, and from which address. There is no code path in the application that edits or deletes an audit entry.
Accounts and sessions
The application itself
Your data
We are not certified to ISO 27001 or SOC 2 for this product. The controls above are real and you can hold us to them, but they have not been audited by a third party, and we will not display a badge we have not earned.
Your data is hosted outside Nigeria, currently in the United States. If your organisation needs it held in a particular region, talk to us before signing up rather than after.
No system is unbreakable, and anyone telling you otherwise is selling something. What we can promise is that the boring controls are actually in place, that we will tell you plainly when something is not, and that if we get something wrong you will hear it from us first.
Found something, or need detail for a security review? billing@suwebatu.co.uk. We would rather hear it from you than read about it.
Start your free trial