Skip to content
nekoledger

Security

Your books are not a playground.

Neko has exactly the permissions it needs, and no more. These are the commitments the product is built on.

  • Data in the Netherlands

    Database, files and processing run in Google Cloud, region europe-west4 (Eemshaven). The language models run within the EU.

  • Neko never pays

    The bank connection is read-only through a regulated PSD2 provider. There is no payment scope. You pay a payment proposal yourself, in your own bank.

  • Encrypted tokens

    Access to bank, Exact and Slack is stored encrypted, with keys in a managed key vault.

  • Isolated client data

    Every client lives in its own isolated space in the database. This is tested automatically on every change.

  • Approve with a button

    Anything that touches money or rules runs only after a click from someone with the right role. The button executes exactly what was proposed.

  • Immutable audit log

    Every booking, rule and approval is recorded. The log cannot be edited or deleted.

  • Documents are data

    What an invoice says is information, never an instruction. Neko does not follow instructions written in a document.

  • Fraud signals

    Changed IBAN, unverified sender, duplicate invoice number: Neko blocks and asks for verification.

Questions about security or a data processing agreement?