Listra processes invoices, payment data, vendor information, and contract terms. We built the platform with encryption, access controls, audit trails, and tenant isolation at the core. Below is exactly how each works.
The controls that finance and IT leaders want to verify before signing a security questionnaire.
Isolation is enforced at every layer, not bolted on at the application level. Listra's reasoning on a given invoice draws only on that customer's data, integrations, and policies.
Every layer enforces isolation independently. A failure at one layer is caught by the next. Customer A's reasoning never sees Customer B's data.
Finance and IT leaders are right to ask what a vendor will not do with their data. The boundaries below are not optional. They are how the platform was built.
Customer data is not used to train models that serve other customers.
Listra's reasoning on your invoice draws only on your data and policy.
Your data is never sold or shared with third parties for any commercial purpose.
No autonomous GL posting outside the policy and thresholds you configure.
Full detail is available in our security questionnaire and DPA. The summaries below cover what most finance and IT teams ask first.
AES-256 at rest. TLS 1.2 or higher in transit. Keys managed via AWS KMS with documented rotation policies.
AWS infrastructure with network segmentation, hardened images, and continuous monitoring. Multi-tenant with company-level isolation at the API, database, and query layers.
Continuous backups with point-in-time recovery. RPO and RTO targets defined per tier. Detail in the security questionnaire.
SAML 2.0 SSO via your identity provider. SCIM automates provisioning and de-provisioning where supported.
Thirty permission categories with action-level granularity. Pre-built roles for AP Specialist, AP Manager, Controller, CFO, and Admin. Full customization available.
Listra ships in Copilot mode for every exception type. Autopilot is enabled per exception type only after you review accuracy data and authorize the change.
For security questionnaires, our sub-processor list, and incident reporting policy, contact security@listra.ai.