Data security

How we handle your information

This page describes the controls that are actually in place today. Where something has not yet been formally verified or finalised, we say so plainly rather than stating it as fact.

What information we receive

Through the public website we receive only the details you submit in the process-review enquiry form: your contact details and a description of your current process. The public enquiry form does not accept file uploads.

Are files received during the initial assessment?

No files are collected through the public website. Sample files are only exchanged after an initial review, by arrangement, and data should be anonymised where practical.

How files are transferred

When you run a workflow, you upload your source file through the Rekeyless portal, which requires you to be signed in. Uploads travel over an encrypted HTTPS connection.

Your source file is processed in memory to produce the import-ready output — the original file you upload is not written to disk or kept in our database once the run has finished. We keep only the resulting output file, the exception report, and basic run details such as the file's name and the number of rows.

Any sample files shared before a workflow is set up are exchanged by arrangement rather than through the portal, and should be anonymised where practical.

Where information is stored

Enquiry submissions are stored in the application database and are accessible only to authenticated administrators. Form submissions are not exposed through any public URL.

Your account details, workflow configurations, lookup tables and generated output files are held in a managed MongoDB database, running on cloud infrastructure provided by the Emergent platform (a managed Kubernetes environment).

We have not independently verified the physical location or region of the data centre used for the production deployment. For that reason we do not currently claim UK or EU data residency. If a specific storage region matters to you, please ask and we will share the details we are able to confirm.

Who can access customer information

Access to enquiry data requires an authenticated administrator account. Customer workflow accounts can only access their own data.

How long files are retained / requesting deletion

Source uploads: the file you upload is processed in memory and is not stored after the run has finished.

Generated output files and exception reports: these are saved against your account so you can download them from the portal. They remain available until they are removed manually — we do not currently apply an automatic deletion schedule.

Lookup tables and workflow configurations: these are kept so your workflows continue to run, and remain until an administrator removes them.

Account information: retained for as long as your account is active.

We do not yet operate an automatic retention or deletion timetable. If you would like specific data, output files or an account deleted, please contact us and we will action the request manually.

Do we use your data to train AI models?

No. This service does not use artificial intelligence to process your data, and your data is not used to train any AI model.

Sage Intacct credentials and direct posting

The service does not require your Sage Intacct login credentials. We do not post directly into Sage Intacct. We produce import-ready files that your team reviews and imports, keeping final control inside Sage Intacct.

How customer workflows are separated

Each customer workflow is configured and stored separately, associated with that customer's own account. One customer cannot access another customer's workflow or files.

How public enquiry data is protected

The enquiry form includes basic spam protection and server-side validation, requires explicit consent, and submissions are only viewable by an authenticated administrator.

Not yet claimed

We do not claim any of the following unless and until they are formally in place: specific encryption standards, security certifications, ISO accreditations, cyber insurance, compliance certifications, penetration testing, defined data-centre locations, or backup arrangements.