— Legal

Security

Last updated: June 22, 2026

Saevel handles sensitive financial data -- bank transactions, EINs, invoices, donor records, AI-generated tax suggestions. This page describes the controls we put in place to protect it.

Encryption

  • In transit: TLS 1.3 on every request between your browser and Saevel, and between Saevel and every sub-processor.
  • At rest: integration tokens (QuickBooks, Quiltt, etc.) and taxpayer IDs are encrypted with AES-256-GCM before being written to the database. Uploaded documents are only served through signed links that expire.
  • Backups: daily encrypted snapshots, retained 30 days.

Tenant Isolation

Every database row carries an entity_id. Every request for an entity's data first checks that you are a member of that entity, and every query filters by its entity_id, so one entity's data is invisible to another.

Authentication

  • Passwords stored as salted scrypt hashes.
  • Sessions are httpOnly cookies backed by the database, so signing out or changing your password ends them on the server.
  • Role-based access within each entity: owner / accountant / viewer.

Integration Tokens

  • OAuth tokens (QuickBooks, Xero) are stored encrypted and rotated automatically via refresh tokens.
  • Webhook signatures are verified for every inbound webhook (HMAC-SHA256, 5-min timestamp window).
  • API keys (Stripe, HighLevel PIT) are restricted-scope where the provider supports it.

AI Privacy

Anthropic Claude is used for transaction categorization, receipt OCR, invoice OCR, and audit suggestions. Anthropic's API provides zero data retention -- they do not train on your data, and they do not retain your prompts. We send only the minimum data needed for each call (a single transaction or document at a time, not your full ledger).

Infrastructure

  • Hosted on Saevel's own server. The database and the application are reachable only from that server; the public site is the one entry point.
  • Production secrets live in the server's environment file and are never committed to git.
  • Audit logging on every transaction modification: who changed what, when, from what value.

Reporting a Vulnerability

Found a security issue? Please email sara@sparkdigitalinc.com with details. We respond within one business day and don't pursue legal action against good-faith researchers.