Security

Your business data, protected with care

EZY Invoice is built with security baked in — encrypted connections, hashed credentials, isolated tenant data and regular backups. We follow industry best practices so you can invoice with confidence.

How we protect you

Security pillars

The foundations that keep your invoices, customers and financial records safe.

Encryption in transit & at rest

All traffic between your browser and EZY Invoice is encrypted over HTTPS/TLS. Sensitive data is protected on disk so it stays unreadable if storage is ever compromised.

Access controls & least privilege

Internal access is restricted on a need-to-know basis. Administrative actions are limited to authorised staff and gated behind strong authentication.

Secure infrastructure & backups

We host on reputable cloud infrastructure with regular automated backups, so your data can be recovered in the event of hardware failure or accidental loss.

Continuous monitoring

System activity and important administrative changes are logged and monitored, helping us detect unusual behaviour and respond quickly when something looks wrong.

Role-based permissions

Decide exactly who on your team can create invoices, manage vendors, view reports or change settings. Fine-grained roles keep sensitive areas in the right hands.

Data ownership & export

Your data belongs to you. Export your invoices, customers and records as PDF or structured files whenever you need them — no lock-in.

Our practices

How your data stays safe

Security isn't a single feature — it's a set of habits applied across the whole product. Here's how we protect your company's information day to day.

Encrypted connections

Every page and API request is served over TLS, so data moving between you and EZY Invoice can't be read in transit.

Hashed passwords

Account passwords are never stored in plain text. They're salted and hashed using modern, industry-standard algorithms — so even we can't read them.

Multi-tenant isolation

Each company's data is scoped to its own account. Company-level scoping is enforced throughout the application so one business can never see another's records.

Regular backups

Automated backups run on a routine schedule, giving us a reliable path to recover your data if the unexpected happens.

Audit logging

Sensitive and administrative actions are recorded, creating an accountability trail that supports monitoring and investigation.

Honest about our posture

We align our controls with widely recognised best practices. We don't claim formal certifications such as SOC 2 or ISO 27001 — we'd rather be upfront than overstate. Questions? See our Privacy Policy and GDPR statement.

TLS Encrypted everywhere
Daily Automated backups
RBAC Granular permissions
100% Your data, exportable

Found a vulnerability?

We take security reports seriously. If you've discovered a potential issue, please get in touch so we can review and address it responsibly. We appreciate the help of the security community.