These terms apply to the SaptOne Invoice website and subscription service. If a separate written agreement applies to your organisation, that agreement controls to the extent of a conflict.
Security programme
We use layered administrative and technical safeguards, including authenticated access, permission controls, tenant separation, input validation, audit records and controlled production access.
Payments
Payment mandates and credentials are collected by the selected payment gateway. SaptOne Invoice stores operational references and payment status, not complete card, bank-account or UPI credentials.
Account protection
Users should use a unique password, protect email and OTP access, review team permissions and sign out of shared devices. Notify info@saptone.in immediately if you suspect compromise.
Data resilience
We apply access controls and operational recovery practices designed to protect service data. Customers should also export and retain records according to their own statutory and continuity requirements.
Responsible disclosure
Security researchers may report a suspected vulnerability to info@saptone.in with reproducible details. Do not access other users’ data, disrupt the service, use social engineering or publicly disclose an issue before we have had reasonable time to investigate.
No unsupported certification claim
Security practices evolve with the service. This page describes our approach and does not claim a certification unless that certification is expressly identified by name and current scope.
Need clarification?
Contact our team and include the email address registered with your SaptOne Invoice account.