Home Product Features Integrations Pricing Security Founders About Contact Book Demo
Security Infrastructure

Corporate Ledger Integrity & Encryption Mappings

SubSentry protects company transaction histories and active directory configurations using industry-standard security structures.

Regulatory Standards Compliance

Mapped and verified against strict international privacy and security parameters.

SOC 2 Type II

Tested by independent CPA auditors to confirm operational control over data pipelines.

ISO 27001

Aligned with info security management system criteria to protect organizational networks.

HIPAA Ready

Meets the security rules required to handle medical organizational directories safely.

GDPR Compliant

Fulfills user data deletion rights and information processing safety scopes cleanly.

How We Protect Spend Data

Robust Platform Security Features

Read-Only Scopes

SubSentry requires only read-only scopes. We never request permission to edit directories, modify transactions, or write GL ledger files.

End-to-End Encryption

All transaction statement data and card tokens are encrypted at rest using AES-256 and in transit using TLS 1.3 models.

Granular RBAC

Set admin rights precisely. Finance heads can see global outlays, while department leads can only examine their own team's software.

Security Architecture Whitepaper

Read our technical architecture layout, detailing data processing pathways, Plaid API links, and encryption models.