Security
Last updated: July 2026
1. Encryption
All data in transit is encrypted with HTTPS/TLS. Invoices and documents you upload are stored encrypted, in a private storage bucket accessed only through time-limited signed links.
2. Data isolation
Every table in our database enforces row-level security, so your organization's invoices, clients, and vendor records are scoped to your account at the database layer, not just in application code. No organization can query another organization's data.
3. Account protection
- Two-factor authentication — add an authenticator app as a second sign-in factor from Settings.
- Login history — review recent sign-ins to your account at any time.
- Team access controls — manage which team members can view or approve invoices for each client.
- Account access notifications — get notified of sign-ins from a new device or location.
4. Audit trail
Every action on an invoice — extraction, correction, exception resolution, approval, and sync — is recorded in a tamper-evident, hash-chained audit log. Each entry cryptographically links to the one before it, so the log itself can be verified for integrity, not just read.
5. Approval controls
Nothing reaches Tally or Zoho Books without a human sign-off from your team. Approvals and rejections are attributed to the person who made them, and every sync carries the evidence trail that verified it.
6. Responsible disclosure
If you believe you've found a security issue in Legiqo, please report it to security@legiqo.co. We ask that you give us a reasonable window to investigate and fix an issue before disclosing it publicly.
7. More information
See our Privacy Policy for what we collect and how it's used.