Trust & security
How rekonfi handles your data. What we do, where it lives, and what we’re still building.
Last reviewed: 1 August 2026
Where your data lives
rekonfi runs in the United Kingdom. The application, its database and its cache are all hosted in London. Some processing, including the AI that reads your invoices, runs in the European Union. Your data is not transferred outside the UK and EU.
How it’s protected
In transit, everything is encrypted with TLS.
At rest, the credentials that connect rekonfi to your accounting software are encrypted with AES-256-GCM. Each one is cryptographically bound to its own record, so a credential lifted from one place cannot be decrypted anywhere else. Keys are versioned, so they can be rotated without taking the service down.
Your accounting connection
rekonfi connects to QuickBooks, Xero and Sage over OAuth 2. We never see or store your accounting software password.You grant access on your provider’s own sign-in page, and you can disconnect at any time from Settings.
What we record
Every capture, extraction, publish and connection change is written to an audit trail with a timestamp and the account that caused it. It exists so that when you ask why a bill posted the way it did, there is an answer rather than a guess. Audit records are archived on a schedule and kept separate from your live data.
Before anything reaches your ledger
Every bill is checked against what rekonfi has already processed before it posts. Anything the AI is not confident about is held for a human to look at rather than pushed through.
Your data is yours
You can request a full export of your organisation’s data, or its deletion, at any time. Deletion removes your documents, extracted data and connections. Email contact@rekonfi.com and we’ll action it.
Service providers
rekonfi uses a small number of service providers for hosting, storage, AI extraction and email. Each is bound by a data processing agreement and each processes data in the UK or EU. A full list, naming each provider and what it processes, is provided with our Data Processing Agreement.
Reporting a security problem
If you believe you have found a vulnerability, our security disclosure policy explains how to report it, what’s in scope, and our good-faith safe-harbour commitment.
What we’re still building
We’d rather tell you what’s in progress than let you assume it’s done.
- Two-factor authentication on rekonfi accounts: Q3 2026.
- Off-site, immutable backups: specified, Q3 2026.
- Formal certificationsuch as SOC 2 or ISO 27001: not held. We’re an early-stage company and we’d rather say so than imply otherwise.