Spends Control
Security & trust

Clear protection. Clear answers.

Understand the controls available today without promises about certifications or services that have not been verified.

Workspace isolation

Records are scoped to the organisation and checked by the server before access.

Role-based access

Owners control who can view, edit and approve operational records.

Authentication

Email/password authentication and optional two-step verification are supported. Additional providers are available only when configured.

Sensitive credentials

Stored credentials use server-side protection and controlled access. They are excluded from general notification content.

Activity and accountability

Relevant business and account changes appear in activity history for permitted users.

Questions and incidents

Contact info@spendcontrol.com for security questions. Request verified operational details before relying on a specific certification, residency or retention requirement.

We do not claim SOC 2, ISO certification, end-to-end encryption or a guaranteed uptime percentage. Backup schedules, retention and contractual commitments must be confirmed for the service you purchase.
Clear answers

Security & trust questions

Which workspace controls should I check before using the service?

Understand the controls available today without promises about certifications or services that have not been verified. For security & trust, check workspace isolation, role checks, credentials, account recovery and two-step verification. Use current source information rather than an assumed value.

What account and access information should an administrator verify?

Records are scoped to the organisation and checked by the server before access. The scenario on this page concerns an owner granting a teammate access to the records needed for an assigned task. The person responsible for that work should confirm the details with the appropriate workspace owner.

Who should receive permission to view sensitive operating records?

Owners control who can view, edit and approve operational records. Missing information about workspace isolation, role checks, credentials, account recovery and two-step verification should be corrected in the relevant source section before relying on a result.

Why should I inspect the source record during an access review?

Email/password authentication and optional two-step verification are supported. Additional providers are available only when configured. Keep the outcome of an owner granting a teammate access to the records needed for an assigned task attached to its source record, with the responsible person and the completed action.

Does a security review establish an independently certified outcome?

Stored credentials use server-side protection and controlled access. They are excluded from general notification content. Security & trust focuses on understand the available controls and verify specific contractual requirements. The page links to the sections relevant to that purpose.