Security
How we protect your data
Expensevues holds receipts and card spending for many companies. Here's how we keep each company's information safe and separate.
Card data
- We store only the last 4 digits of each card. There's nowhere to enter a full card number, expiration date or security code.
- Text fields refuse anything that looks like a full card number, and card numbers in forwarded emails are masked.
- There's no connection to your bank or card issuer, so there are no banking credentials to protect.
Each company's data stays separate
- Every company has its own web address, such as acme.expensevues.com.
- Every request is checked against the company it belongs to, so people at one company can't see another company's data.
- A sign-in only works on your own company's address.
Signing in
- Accounts are created by invitation only. There's no public sign-up.
- Admins and managers must use two-factor authentication. A company can require it for everyone.
- Sessions time out, and sooner for admins and managers.
Receipts
- Receipts are stored privately. Links to view them expire after a few minutes, and are only created for people allowed to see that receipt.
- Photos are processed on our servers to remove location and camera details before they're saved.
- Receipts saved offline stay on the phone until they're uploaded, then are removed from the phone. Signing out clears them too.
Encryption and backups
- All traffic uses HTTPS, and browsers are told never to use an unencrypted connection.
- The database connection is encrypted, and data is encrypted where it's stored.
- Backups run every day, are encrypted, and are kept in separate storage.
Activity history
- Sign-ins, approvals, exports, setting changes and receipt views are recorded.
- The history can't be edited or deleted, and company admins can review their own company's activity.
Questions?
If you have a security questionnaire or want more detail, get in touch and mention it in your message.