Security approach
Tockly uses layered technical and organisational safeguards appropriate to an online invoice-follow-up service. These include encrypted connections, access controls, protected integration credentials, restricted administrative access and incident-response procedures.
Account protection
- Passwords are uniquely salted and hashed using PBKDF2 with SHA-256 and are never stored in readable form.
- Sessions are stored in Tockly’s database and users are signed out after 15 minutes of inactivity.
- Connection credentials for services such as Xero, MYOB and QuickBooks are encrypted before storage.
- Account activity and service errors may be logged for security and troubleshooting.
Data storage
Tockly runs on the OpenAI Sites platform and uses Cloudflare Workers, D1 and R2 for application computing, structured records and uploaded invoice files. Cloudflare’s global infrastructure may process information in multiple countries. Reminder email is delivered through Resend by default. A customer may instead authorise send-only access to its Microsoft 365 or Google mailbox. Tockly does not request inbox-reading permission for that connection.
Payments and integrations
Where Stripe-hosted checkout is offered, complete card details are entered with Stripe and are not stored by Tockly. Tockly uses accounting connections only to retrieve the customers, invoices and payment status needed for follow-up. Disconnecting an accounting service stops future access but does not erase previously imported records.
Responsible use
Customers should use unique passwords, protect their devices, grant access only to authorised people, check imported invoice information and avoid uploading sensitive information that is not needed for invoice follow-up.
Report a security issue
Please report suspected vulnerabilities or unauthorised access privately to contact@tockly.ai. Include enough detail for us to investigate, but do not send another person’s sensitive information unnecessarily.