Last updated: August 30, 2026
Security and AI
Technical detail without fluff. The same truth as the policy, more concrete.
AI — which model and what they retain
By default, chat and document analysis go through Anthropic's API with Pavora's key. They do not train on API data. Default retention is 30 days (flagged prompts up to 2 years). We have no Zero Data Retention agreement.
On Pro you can connect your own key (Anthropic, OpenAI, Mistral, or Google); then that provider's terms and any ZDR agreement you have apply, and Pavora tokens are not deducted.
Auto-masking is on by default: personal ID numbers, company registration numbers, IBANs, email, phone, bank account numbers, addresses, person names, and supplier and customer names are replaced with random placeholders before anything is sent to the model.
When the agent reads the ledger through tools, it pauses — the tool result goes back to your browser, is masked there, and only then does the agent continue.
On Pro the organisation owner can connect their own key (Anthropic, OpenAI, Mistral, or Google). It is stored client-encrypted in the same shared org vault as OAuth tokens — ciphertext with us, key material only on devices that can unlock the vault. Everyone in the organisation uses it for chat. On each call the browser decrypts the key and sends it in flight (X-Pavora-Vault); we use it in memory and do not store plaintext. Removing the key in Pavora only deletes our ciphertext — rotate or revoke the key at the provider if you want to shut off access.
| Model | Provider | Trains on API data | Retention | Purpose |
|---|---|---|---|---|
| Claude Sonnet 5 | Anthropic | No | 30 days | Chat and document analysis |
| Claude Haiku 4.5 | Anthropic | No | 30 days | Topic filter before the main model runs |
platform.claude.com/docs/en/manage-claude/api-and-data-retention
Cryptography
In transit: TLS. At rest with Supabase: their disk encryption (AES-256) — that protects against a stolen disk, not against us. At the application layer: per-organization envelope encryption (AES-256-GCM) for Pavora Huvudbok, agent proposals, OCR extractions, audit logs, and notifications — the same server-held key we can use for support.
Connections to Fortnox, Visma, Bokio, and Kleer store OAuth and API tokens client-encrypted in the organisation's shared org vault (AES-256-GCM). We store ciphertext and DEK wraps — not readable plaintext. Your browser decrypts on each call and sends the token in flight via the X-Pavora-Vault header; the server uses it in memory to proxy to the provider. SIE and snapshot files in export/import history are sealed with the same org vault DEK before upload to object storage — we store ciphertext only and cannot read file bytes at rest. Disconnecting deletes our ciphertext — revoke or rotate the token at the provider separately. Exception: Stripe integration keys for nightly bank automatch are stored server-encrypted (AES-256-GCM) so cron can sync without a signed-in user.
In the browser: AES-256-GCM via Web Crypto for private chats, receipts, reports, mask maps, and the organisation's shared org vault (OAuth tokens, BYOK keys, and SIE/snapshot history), where the key derives from your recovery key and the org vault DEK never leaves the device in plaintext. We cannot open ciphertext in the personal vault or org vault. Vouchers from Fortnox/Visma that are cached for reports are stored encrypted in the personal vault on the device.
Shared chats (when you invite colleagues) are end-to-end encrypted: a content key is generated in the browser and sealed (ECDH P-256) individually to each invitee's public key — only their device can unlock it, and we only ever store ciphertext. The receipt inbox is a similar but separate exception: attachments sit with us for 30 days so every org member can pull them, then it is deleted.
Pavora Huvudbok — demo environment · 24 h
The demo environment (Pavora Huvudbok) is stored envelope-encrypted in our database with a server-held per-organization key — not in the client vault. It is for trying chat, approvals, and bookkeeping views before you connect Fortnox etc. If any bookkeeping in the demo environment is older than 24 hours, the entire demo environment for that organization is wiped every night — vouchers, invoices, bank, payroll, chart of accounts, and fiscal years. Production books should live with your accounting provider.
We see data in flight
Fortnox and Visma require a confidential OAuth client. Our server has to exchange the code for tokens and proxy the API calls. “We do not store books” is not the same as “we never see data”. LLM calls travel the same path: masked text leaves the device (Anthropic by default, or your own key on Pro). When the agent calls tools that read the ledger, the server pauses and sends the result back to your browser — it is masked there before the agent continues. With “Ask before send” you get a preview of both messages and tool results before they reach the model.
Found a vulnerability?
Email kontakt@pavora.se with the subject “Security”. We take it seriously and will reply.