Security at Rxolve
Last updated: August 2026
Rxolve reads your accounting platform and bank data to produce a data-driven cash-management plan. That means we handle information most businesses treat as confidential. This page sets out how we protect it.
For the legal position on data protection, see our Privacy Policy. For our regulatory status, see our Regulatory Statement.
Data isolation
Every customer organisation’s data is isolated at the database layer. Isolation is enforced on each individual query by the database itself, not by application code that could be bypassed by a bug. No query can return another organisation’s records.
What our AI is shown
Rxolve uses LLMs to reason over your data. Two controls govern what reaches it.
Field-level minimisation. Each processing step receives only the fields that step requires. Counterparty contact details — names, email addresses, telephone numbers — are withheld from every step except drafting a message to that counterparty.
Credential exclusion. Access credentials are never included in data sent for processing. Every outbound payload is scanned for credential material before transmission and blocked if any is found.
Our partner LLMs will not use API inputs to train their models.
How we learn
Rxolve improves by learning patterns across all customers — how payment timing varies by sector, which signals precede a late payment. This uses anonymised and aggregated data only. Your financial records, counterparty names and contact details are never used and never enter a training dataset.
This is enabled by default and you can opt out at any time in your settings.
Connections and access
Connections to your accounting platform are read-only. Bank data and payment initiation run on open banking under PSD2, through FCA-authorised account information and payment initiation providers. You authorise every connection under strong customer authentication and can revoke any of them from your settings.
Rxolve never holds your money. Funds remain in your own accounts at all times.
Encryption
Data is encrypted in transit using TLS 1.3 and at rest using AES-256.
Retention and erasure
Every category of data we hold carries a defined retention period. When you remove a counterparty, their contact name, email address and telephone number are erased automatically within 30 days. Transaction records are retained for audit and statutory purposes with the personal details removed.
On account closure, your data is available for export for 30 days and then deleted from live systems within 90 days.
Audit trail
Every recommendation Rxolve produces is recorded with the data that drove it, the alternatives considered, and who approved or declined it. Approvals are logged with the acting user and timestamp. You can export this record at any time.
Sub-processors
We currently use five sub-processors: Anthropic for AI processing, Supabase for database and authentication, Vercel for application hosting, Stripe for payment processing, and Plausible for cookieless analytics. Each is named in our Privacy Policy, with what it processes and where.
We may add or replace sub-processors as the product develops. Where we do, we will update this page and notify customers in advance.
Certifications
Rxolve is built to UK GDPR and the Data Protection Act 2018. SOC 2 Type II and ISO 27001 attestations are on our roadmap. We do not currently hold either, and we will not claim otherwise.
Reporting a vulnerability
If you believe you have found a security issue, email security@rxolve.co. We will acknowledge within two working days. Please do not disclose publicly until we have had a chance to respond.