Trust, stated plainly
Expense management security, read-only by design
Expense management security starts with what a tool can do with your money. Spendnotify can see spend on your existing cards and accounts, and it can never move, hold or block a dollar. This page states what that means in practice, and what is planned rather than shipped.
Architecture
We can see spend. We can never move it.
Spendnotify connects to your corporate cards and bank accounts through read-only links whose only capability is reading transaction data. There is no payment rail in the product: no card issuing, no transfers, no holds, no bill pay. That is not a policy promise that could drift, it is the shape of the system. A compromise of an alerting tool that cannot transact is a data problem, never a money-movement problem, and we chose that trade on purpose.
The same honesty applies in the other direction: Spendnotify is not a bank, not accounting software, and it cannot stop a payment that is already authorized. It compresses the time between "something crossed a line" and "the right person knows" from weeks to moments. How that loop works end to end is on the real-time expense tracking page.
Practices
How data is handled
Encryption in transit and at rest
Connections to the site and to data sources use TLS, and stored data is encrypted at rest. Signup records are kept in an encrypted datastore with access limited to the team.
Data minimization
The alerting engine needs transaction metadata: date, amount, merchant, category, and who spent. It does not need card numbers, banking credentials for payments, or documents, so it does not take them. Today, pre-launch, the only personal data we store is the early-access signup itself.
Access controls
Internal access follows least privilege: production data is reachable only by the people who operate the system, over authenticated, logged channels. In the product, plans carry seat limits, and roles and permissions are planned for the Enterprise tier.
The demo runs in your browser
The alert simulator parses and analyzes pasted transactions locally; pasted data never leaves your browser. Only sample-company runs make one optional network call to write a plain-English sentence about a flagged sample pattern, and the demo works fully without it.
For larger teams
Enterprise controls, planned for launch
Spendnotify is in early access, so we say "planned" where other sites print badges. These are the commitments scoped for the Enterprise tier at launch; none of them is live today, and we claim no certifications we do not hold.
- SSO and SAML
- Roles and permissions
- 99.9% uptime SLA
- Security review + DPA
- Invoicing and PO
- Dedicated CSM
The Enterprise column on the spend management software pricing page shows how these fit the plans, and the CFO dashboard page covers what the decision maker sees day to day.
Early access
Questions a security review would ask?
Email team@spendnotify.com and we will answer plainly, including "not yet" where that is the honest answer.