Security & Trust

Security and trust for your business documents.

Plain answers to the questions businesses ask before putting invoices and customer details into a tool: who can see what, how documents are shared, what the providers do, and what AI can and cannot touch.

This page describes how Hectile is designed to work. It does not claim certifications or audits.

01

Accounts and membership

Access control

You sign in with your own account. Access to an organization is granted by membership: an Admin invites people by email, and each member sees only the organizations they belong to. Admins manage settings, brands, billing and members; Members work on documents and customers. Removing a member revokes their access to the organization.

02

Separation between organizations

Data boundary

Every organization is a separate boundary. Documents, customers, items, payments and members belong to one organization and are never shown inside another. Someone who is authorized in two organizations works in one at a time and switches between them; membership in one grants nothing in the other.

Brands inside one organization are not separate restricted team spaces at launch: every member of the organization can work across all of its brands.

04

What never appears on a customer-facing document

Customer-facing vs internal

Internal memos, private payment references, team notes and your organization's member list are never rendered on the PDF or the public document view. Only the fields designed for the customer — brand details, line items, totals, tax breakdown, payment instructions and customer-facing notes — are shown.

05

Issued-document integrity and payment history

Records

Finalizing a document assigns its number and fixes its content. Corrections happen by issuing a new document rather than silently editing an issued one, so what your customer received stays what your records show. Every recorded payment keeps who recorded it, when, the amount, method and reference.

06

What our providers do

Providers

Hectile runs on established service providers for hosting and sign-in abuse protection, database and file storage (including account and sign-in records), authentication and document email, and billing your Hectile subscription. Each handles only its part. Subscription billing is separate from your own invoicing: your customers pay you through your own methods, and you record those payments in Hectile.

07

AI's limited role

AI

AI Quick Create reads the request you type and the organization data needed to draft — customer names, saved items, tax profiles, terms — and returns a draft you review. It cannot finalize, send, record payments or change settings. Your request is processed by an AI provider to produce the draft; the provider's role is listed with the other providers.

08

When access ends

Retention

If a cancelled trial or a subscription ends, the organization becomes read-only: you can still sign in, view records and download issued PDFs, and existing valid links keep working unless you revoke them. Ending access does not automatically delete your records.

09

Connections in transit

In transit

Connections between your browser and Hectile use encrypted transport (HTTPS/TLS).

What your customer sees

Customer-facing fields and internal notes are kept apart.

The PDF and the public document view show only the fields designed for the customer. Internal memos, private payment references and your team's activity stay inside your organization.

Revoking a link

Turn off a link without touching the invoice.

If a link reached the wrong inbox or is simply no longer needed, revoke it or generate a new one from the document. The old link stops opening; the finalized document, its number, its PDF and its payment history stay exactly as they were.

Your part

A few habits that keep your documents safe.

Hectile protects your organization's data. The controls you hold — accounts and links — are yours to manage.

  • Protect your account. Keep your sign-in email secure. Never share sign-in codes, authenticator codes or recovery codes. Remove members who leave.
  • Share document links deliberately. Anyone with a valid link can open that document. Send it to the person who needs it.
  • Revoke when appropriate. If a link was sent to the wrong address or is no longer needed, regenerate or revoke it from the document.
  • Keep internal notes internal. Use the document's internal memo for anything the customer shouldn't see; it never appears on the PDF or public view.

Report a security concern

Found something that doesn't look right? Use the contact form with the subject "Security report". Describe what you saw; please don't include live credentials or other people's data.

Contact us about security

Related documents

The legal detail behind this page lives in the policies below.

Questions about your business data?

Ask before you start. Tell us what you need to know about accounts, documents, links or providers and we'll answer directly.

Contact about securityPrivacy Policy