Security and Data Confidentiality

Last updated: July 14, 2026

Our approach

Sarebel uses administrative, organizational, and technical measures designed to protect Customer Content against unauthorized access, disclosure, alteration, loss, and destruction.

No online service can guarantee absolute security. Sarebel continuously evaluates safeguards according to the nature of the service, the sensitivity of the information, and reasonably foreseeable risks.

Separation between customer organizations

Each Sarebel customer organization is assigned a separate organizational account.

Sarebel is designed so that authorized users of one organization cannot access another organization’s Customer Content through normal product functionality.

Sarebel does not provide stores with access to another store’s:

  • Invoices or document images.
  • Extracted invoice information.
  • Supplier or customer identities.
  • Prices, costs, quantities, or purchasing activity.
  • Account notes.
  • Search history.
  • Usage records associated with that store.
  • Other confidential commercial information.

Limited internal access

Access by Sarebel personnel and contractors is limited according to role and legitimate business need.

Sarebel personnel may access Customer Content only where reasonably necessary to:

  • Provide support requested by the customer.
  • Operate, maintain, or secure Sarebel.
  • Diagnose a technical problem.
  • Investigate suspected fraud or misuse.
  • Comply with applicable law.
  • Perform another activity authorized by the customer.

Personnel and contractors with access to confidential information are subject to confidentiality obligations.

Service providers

Sarebel may use contracted cloud hosting, storage, database, document-processing, authentication, security, monitoring, communication, billing, and support providers.

These providers may process limited information only as reasonably necessary to perform services for Sarebel. Sarebel does not authorize them to use Customer Content for independent advertising or to train general-purpose AI models.

AI and OCR confidentiality

Documents may be processed by automated document-processing or AI service providers acting for Sarebel.

Sarebel does not use Customer Content to train general-purpose artificial-intelligence models and does not authorize its service providers to use Customer Content for that purpose, unless the customer separately and expressly opts in in writing.

Aggregated and de-identified information

Sarebel may internally use aggregated or de-identified information to operate, secure, troubleshoot, measure, and improve the service.

Sarebel will not treat information as de-identified where it can reasonably identify a particular store, business, person, supplier, customer, invoice, transaction, or confidential commercial activity.

Sarebel will not disclose one store’s information to another store merely because the store’s name has been removed. Information must not be reasonably re-identifiable from the information itself or in combination with other reasonably available information.

Customer responsibilities

Customers are responsible for:

  • Protecting account credentials.
  • Using unique passwords.
  • Restricting account access to authorized personnel.
  • Removing users who no longer require access.
  • Protecting devices used to access Sarebel.
  • Reviewing account permissions.
  • Promptly reporting suspected unauthorized access.

Suspected security incidents should be reported to security@sarebel.com.