Security & Data Handling
Last updated: August 22, 2026
You're about to upload an aging report with your customers' names and balances on it. Here's exactly what happens to it.
We wrote this page because we'd want to read it before uploading our own clients' AR. No marketing language, no badges we haven't earned.
Your raw file never touches our servers
When you upload an AR aging report, the spreadsheet is parsed in your browser. Only the extracted data (client names, invoice numbers, balances, and dates) is sent to our servers and stored. The original file is never uploaded and never retained.
Where your data lives
Your data is stored in a managed PostgreSQL database hosted by Neon, running on AWS in the United States (US East). The application runs on Vercel. Your data does not leave the United States.
Encryption
Data is encrypted in transit over TLS (the site enforces HTTPS with HSTS). Data is encrypted at rest by our database provider; see Neon's security overview for their current specifications.
Tenant isolation
Every record in ReceivAR is scoped to your organization. Queries are filtered server-side on every request, and no endpoint returns data outside the authenticated user's organization. The codebase, including tenant isolation, underwent an independent third-party security review in August 2026, and we re-verify isolation with each release. We have not yet commissioned a formal penetration test.
AI-generated letters
When you choose AI letter generation, the details needed to draft the letter (client name, invoice numbers and amounts, aging totals, and prior contact history) are sent to Anthropic's Claude API to produce the draft. Anthropic does not train its models on commercial API data by default (see their commercial terms). If you prefer to keep client data out of any third-party AI entirely, template-letter mode produces letters with no external AI calls at all.
Every letter, AI or template, is drafted for your review. Nothing is sent to your customer without you approving it.
Payments
We don't store card numbers. Billing is handled by Stripe, and your payment details go directly to Stripe, never through our servers.
Who can access your data
Access is limited to the users in your organization. On our side, access is limited to the founder, for support and debugging, and only when needed. We don't sell, share, or license your data to anyone.
Retention and deletion
If you close your account or ask us to delete your data, we remove it from our active systems within 30 days; encrypted backups age out within 90 days. You can export your data as CSV from inside the app at any time, or request a full export by emailing support@receiv-ar.com. Full details are in our Privacy Policy.
What we don't have yet
We are not SOC 2 certified. We're an early-stage product and we'd rather tell you that plainly than imply otherwise. If SOC 2 is a requirement for your organization, tell us; it helps us prioritize.
Reporting a vulnerability
If you find a security issue, email support@receiv-ar.com. We'll respond within two business days.