Skip to main content

Security

Receipts, ledgers and customer masters are among the most sensitive files any finance team holds. We employ state-of-the-art security measures and undergo regular security reviews from third-party security firms to ensure the highest level of data protection.

Cyber Essentials Certified

ExactRec security practices and controls have been independently audited by experts.

Encryption

Data is encrypted in transit and at rest using the most secure algorithms available.

Zero Data Retention

Your files are never used to train AI models and are deleted permanently once you remove them.

Two Factor Authentication

All internal accounts require two-factor authentication to mitigate the risk of unauthorised access.

Zero-Trust Architecture

ExactRec was architected from the beginning with security in mind. We employ a zero-trust security model, which means that no components or systems can communicate with each other without specific authorisation and authentication.

Anonymised Pilots & UK/EU Processing

A pilot does not need real customer names — only consistent ones — so files can be anonymised before they ever leave your building. Data is processed in UK/EU regions, and where third-party AI inference providers are used we contract for zero retention and no-training terms. Because v1 is file-in, file-out, nothing connects to your live systems at all.

Principle of Least Privilege

Only strictly required access is granted to accounts and personnel to minimise risk.

Automated Security Checks

All code, libraries and operating systems are regularly scanned for vulnerabilities and patches or updates are made to mitigate identified security issues.

Continuous Security Monitoring & Threat Detection

We leverage modern AI tools and run continuous monitoring on our infrastructure. Threat detection monitors for malicious activity and anomalous behaviour to keep systems and data secure.

Secure File Transfer

Pilot files are exchanged over secure, single-purpose links scoped to one engagement and expiring after use, rather than over email attachments or shared credentials.

Account Level Security

All accounts must meet minimum requirements for password complexity. Account sessions are protected through inactivity timeouts.

Regular Access Reviews

Access to systems and accounts is regularly reviewed to ensure no personnel have inappropriate access to systems or data.

Send one month. Get a measured match rate.

The ask is narrow and costs you almost nothing: one month of the three input files, anonymised. From that we report a measured match rate against your current system, and a worked example of lump-sum allocation on your own data.