Approvdit Approvdit.

Automate Your Bill Approvals & Workflows.

Security & Compliance

Effective Date: September 2026  •  Approvdit Technologies  •  [email protected]

This page describes the technical and organizational security measures that Approvdit Technologies ("Approvdit," "we," "us") maintains for the Approvdit approval workflow platform (the "Service"). It supplements the Privacy Policy and Terms & Conditions, which govern data processing and use of the Service.

1. Security at a Glance

Control Implementation
Encryption in transitTLS on all connections
Bank details at restAES, dedicated key class
OAuth tokens at restAES, dedicated key class
2FA secrets at restAES, dedicated key class
Key managementVersioned key rings with rotation support
PasswordsOne-way hashed; never stored in readable form
Two-factor authenticationTOTP, mandatory; hashed recovery codes
Brute-force defenseLogin attempt monitoring with automatic lockout
Audit trailSHA-256 hash chain, tamper-evident
Multi-tenancyOrganization-scoped queries; cross-tenant access blocked
BackupsWeekly, GPG-encrypted, off-site
Breach response24-hour assessment; 72-hour notification
Availability commitment99% monthly uptime (Terms & Conditions, Section 12)

2. Encryption in Transit & at Rest

  • All connections to the Service are encrypted with TLS
  • Vendor bank details (IBAN, SWIFT code, account name, account number) are encrypted at rest with AES — both in the vendor master list and on individual requests
  • OAuth integration tokens and 2FA (TOTP) secrets are encrypted at rest
  • Key separation: bank details, OAuth tokens, and 2FA secrets are each encrypted under independent key classes. Compromise of one key class does not expose data protected by the others
  • Passwords are stored as one-way hashes and are never readable by Approvdit personnel

3. Key Management & Rotation

  • Each key class (bank details, OAuth tokens, 2FA secrets) uses a versioned key ring (v1, v2, and so on)
  • New data is encrypted with the newest key version; existing records remain readable under the key version with which they were encrypted
  • This architecture supports key rotation without data loss or downtime
  • Encryption keys are held in server-side environment configuration, separated from the database and from encrypted data

4. Access Control & Authentication

  • Role-based access control with three roles: Administrator, Auditor (read-only), and User — least privilege by default
  • Two-factor authentication (TOTP) is mandatory for all accounts; recovery codes are stored as one-way hashes
  • Login attempts are logged with IP address and timestamp; repeated failures trigger automatic lockout (brute-force protection)
  • Sessions are terminated instantly upon account deactivation
  • User invitation links expire seven (7) days after issuance
  • New-device logins trigger alerts to the account owner

5. Audit Trail Integrity

Every action on a request is permanently recorded: submission, approvals, rejections, holds, pings, revocations, comments, and attachments.

  • Each audit record is cryptographically chained: its hash is the SHA-256 of the previous record's hash combined with the record's content
  • Modifying or deleting any historical record breaks every subsequent hash in the chain, making tampering detectable
  • Under normal operations, records cannot be edited or deleted by any party, including Administrators and Approvdit personnel (subject to the legal-compulsion provisions of the Terms & Conditions, Section 11)
  • The Smart Revoke function appends corrective entries while preserving original records, keeping the chain unbroken

6. Multi-Tenant Isolation

Approvdit is a multi-tenant platform: multiple Organizations share the application infrastructure, but data is segregated at the database level.

  • Every database query is scoped to the requesting User's Organization ID
  • Cross-tenant access attempts are blocked and rejected, even where a direct record reference is guessed

7. Infrastructure & Sub-Processors

The Service is hosted on infrastructure in the US and EU. Approvdit shares data with exactly three sub-processors, each bound by contractual data protection obligations:

Sub-processor Service Data accessed
RenderHosting, databaseAll data
CloudflareCDN, file storage (R2)Uploaded files
ZohoEmail deliveryEmail addresses

For UK/EU Organizations, Standard Contractual Clauses for international transfers are available on request, consistent with the Privacy Policy.

8. Backup & Data Retention

  • Organization data is backed up weekly using GPG-encrypted, off-site storage
  • Deleted data is removed from the live system immediately and purged from encrypted backups within thirty (30) days
  • Login attempt logs auto-expire after fifteen (15) days
  • Complete data exports remain available for one hundred eighty (180) days following account termination (Terms & Conditions, Section 14)

9. Breach Notification

  • Approvdit assesses the severity of a suspected incident within twenty-four (24) hours of detection
  • Affected Organizations are notified within seventy-two (72) hours of initial detection of a confirmed security breach
  • Notifications include: what happened, the categories of data involved, the remediation measures undertaken, and recommended corrective actions

These commitments match the Privacy Policy (Section 11) and the Terms & Conditions (Section 13).

10. Compliance & Data Protection

  • Approvdit acts as Data Processor for employee and operational data; the client Organization is Data Controller (Privacy Policy, Section 2)
  • For Organizations in the UK/EU, GDPR applies to the processing described in the Privacy Policy; a Data Processing Addendum is available on request
  • Approvdit does not collect or store payment card numbers, government ID numbers, or biometric data; where card payments are introduced, they are handled by the payment processor, not by Approvdit
  • Approvdit has not obtained third-party certifications (such as SOC 2 or ISO 27001) at this time; the controls described on this page are implemented and verified internally
  • These measures are governed by the laws of the Islamic Republic of Pakistan

11. Shared Responsibilities

Security is shared. The Organization is responsible for:

  • Maintaining accurate User lists and deactivating departing Users promptly
  • Keeping login credentials and 2FA devices confidential
  • Implementing segregation of duties and internal controls over its approval workflows
  • Verifying vendor identity and payment instructions — Approvdit does not verify invoice authenticity or detect fraud (Terms & Conditions, Section 15)

12. Reporting a Security Issue

Suspected vulnerabilities in the Service may be reported to [email protected]. Please include a description of the issue and, where possible, reproduction steps. We ask that reporters allow a reasonable remediation window before any public disclosure. Approvdit acknowledges reports and keeps reporters informed of remediation progress.

Contact: [email protected]

Entity: Approvdit Technologies

Registered office: Awaiting Incorporation

© 2026 Approvdit. All rights reserved.