PHP 2.5 per receipt for 2026 👀🥳

Security & trust at SnapSpend

Last updated: July 2, 2026

Finance data is the most sensitive data your business has. Here’s exactly how we treat yours — what we have today, stated plainly, with nothing we don’t.

1. How our trust posture is built

Our backend database partner is SOC 2 Type 2 compliant. Your data sits on SOC-2-audited infrastructure from the moment you sign up. SnapSpend layers its own application and database-level controls (Row-Level Security, role-based access, signed URLs, admin audit logs) on top — designed so we never weaken what we inherit.

2. Where your data lives

SnapSpend uses managed Postgres and object storage in a Southeast Asia region (specific region details available under NDA). Your receipts, parsed data, and exports are stored in-region. During AI parsing, documents are processed by established AI providers under API terms that prohibit using your data to train their models — we never train models on your documents, and we never sell or share them with third parties.

3. Encryption

All documents are encrypted at rest using AES-256, and in transit over TLS 1.3. Document access goes through short-lived signed URLs generated per request — links expire automatically and cannot be reused indefinitely. Your password is hashed with bcrypt; we cannot read it, and neither can our team.

4. Tenant isolation & access control

SnapSpend is multi-tenant, and isolation is enforced in the database itself — not just in application code. Even if an application bug slipped through, the database independently blocks cross-organization access.

  • Row-Level Security on every business table — every query is scoped to your organization at the database layer
  • Role-based access control — viewers, members, admins, and owners each get only the permissions their role allows
  • No self-escalation — roles, plan tiers, credit balances, and account limits are protected at the database level and can only be changed through authorized platform channels
  • Locked-down internals — background processing and privileged database functions are sealed off from direct user access and reachable only by platform services
  • Audit logs of administrative actions

5. Ongoing security practice

Security is not a one-time project at SnapSpend. In 2026 we completed a comprehensive internal security audit covering account permissions, data access paths, sign-in flows, background processing, and file exports — and shipped fixes for every finding. Every release now passes a security-focused review gate before it ships.

One example: exported CSV and Excel files neutralize embedded spreadsheet formulas, so a maliciously crafted receipt can’t execute code when you open your export — while your amounts stay fully usable for calculations.

6. Compliance posture

Inherited from infrastructure (backend database partner + hosting partner): SOC 2 Type 2 · GDPR-aligned data handling.

SnapSpend itself is not yet SOC 2 certified — formal certification is on our roadmap, and we implement SOC 2-aligned controls (RBAC, encryption, tenant isolation, audit logging, release security reviews) today.

Philippine-specific: DPA 2012 alignment (NPC registration in progress) · BIR-compliant output formats (SLSP, 2550M).

BIR / BSP: SnapSpend produces SLSP and 2550M outputs that match BIR’s published file specifications for eFPS submission. We are BIR-compliant by output, not BIR-accredited — no such accreditation exists for receipt-parsing software in Philippine law.

Want documentation? Email security@snapspend.ai — we’ll share our infrastructure partners’ SOC 2 Type 2 reports under NDA.

7. Reliability

  • Uptime target: 99.5% on PRO and MAX tiers (formal SLA on roadmap).
  • Backups: Continuous WAL-streamed backups (managed by our infrastructure partner), with point-in-time recovery available.
  • Incident response: Customers are notified within 24 hours of any confirmed incident affecting their data.
  • Status page: In development.

8. Your data, your rights

You can export everything at any time, in machine-readable format (CSV and Excel). You can request deletion of your account and all associated data — every row, every file, removed within 30 days of your request, no “we keep a backup forever.”

Have a security question we didn’t answer? Email security@snapspend.ai — we reply within one business day.