Lodgeio
Security

Your receipts are business records. We treat them that way.

Expense data is financial data: who spent what, where, on which card. Here is where it lives, who can see it and how it is protected. Plain answers, no badge wall.

Where your data lives

Lodgeio runs in Sydney, Australia. The application is hosted in an Australian region and the database and receipt storage sit in Sydney data centres. Your receipts, claims and account records stay onshore.

Two narrow functions involve overseas processing: email delivery and the AI reading of receipts, both handled by United States providers and both limited to that single task. The Privacy Policy sets out each function we outsource and where it runs.

🔒Encrypted, both directions

All traffic between you and Lodgeio is encrypted in transit with HTTPS, and data is encrypted at rest in the database and file storage.

🏠One company, one boundary

Every company's data is isolated at the database level with row-level security. Queries physically cannot cross from one company into another, whatever the application code does.

👥Access follows roles

Employees see their own claims. Managers see what they approve. Accounts sees what it verifies. Roles are explicit in the product, and administrators control who holds them.

📜Everything is audited

Lodging, approving, rejecting, verifying, exporting, changing a user: each action is written to an audit trail with who and when. The trail exists before anyone needs it.

🔑Passwords done properly

Passwords are stored only as salted cryptographic hashes, never in readable form, and accounts lock after repeated failed sign-in attempts.

🤖AI without the fine print

The AI that reads your receipts processes them to fill in the claim, and its provider does not train models on your documents. Every AI-filled claim is confirmed by a person.

Kept as long as the law asks, then gone

Expense records and their receipts are retained for seven years, the period the Corporations Act requires companies to keep their financial records, which also covers the five years tax law asks for. Accounts can be exported and personal identifiers deleted on request, with the process spelled out in the Privacy Policy. If a data breach ever puts people at likely risk of serious harm, we notify them and the OAIC under the Notifiable Data Breaches scheme.

✓Hosted and stored in Sydney, Australia ✓Encrypted in transit and at rest ✓Row-level tenant isolation in the database ✓Role-based access with a full audit trail ✓Retention aligned to Australian tax law ✓Notifiable Data Breaches scheme compliance

Found something we should know about?

If you have found a vulnerability, tell us at hello@lodgeio.com.au with "Security" in the subject line. We read every report, respond to genuine ones, and will never take action against good-faith research.

Contact us