Security
How Owwyl protects your financial data.
Encryption at Rest
All OAuth tokens, transaction data, and invoice PDFs are encrypted using AES-256. Encryption keys are stored separately from application data and rotated on a regular schedule.
Tenant Isolation
Every record carries an organization identifier, and every read and write is scoped to your organization. No screen and no export returns another organization's data. Cross-tenant isolation is verified by an automated test before any release.
Minimum Permissions
Email: read-only via Nylas. Bank: read-only via Stripe Financial Connections. Xero: invoice and account read/write for bill creation only. We never request permissions beyond what the service requires.
Draft-Only Submissions
New categorizations start as drafts. As Owwyl reaches your confidence threshold on confirmed vendors, submissions become automatic. You control the threshold. New vendors always start as drafts.
Token Management
Xero tokens refreshed every 30 minutes. Stripe FC tokens encrypted with AES-256. Email tokens via Nylas stored encrypted with proactive refresh.
Audit Trail
Every sync operation, categorization decision, and anomaly detection event is logged with timestamps, actor, and reasoning. Full audit history available in your account.