Security
Last updated 23 September 2026
How we protect the invoices, supplier data and accounting connections you trust Tenet with.
Infrastructure
- Hosted on Google Cloud (Cloud Run, Cloud SQL for PostgreSQL, Cloud Storage) in the United States.
- All traffic uses TLS; HTTP Strict Transport Security is enabled.
- Data at rest is encrypted by Google Cloud. Accounting OAuth tokens are additionally encrypted by Tenet with AES-256-GCM.
- Daily automated database backups with point-in-time recovery.
Application
- Every workspace is isolated at the data-access layer; each query is scoped to the signed-in user's workspace.
- Four roles — admin, approver, AP specialist, viewer — with permissions enforced on the server.
- Removing a user or resetting a password ends their existing sessions immediately.
- Rate limits on sign-in, password reset and uploads.
- An audit trail records who approved, corrected or cleared each invoice.
AI processing
Documents are read by Google Document AI and checked by a large language model. Providers process data only to return results to Tenet and are not permitted to use it to train their models. Nothing is posted to your ledger without a person in your team approving it.
Reporting a vulnerability
Email [email protected]. We acknowledge reports within two business days and will not take action against good-faith research that avoids accessing other customers' data.