Trust, built in.

When you hand us financial data, trust is non-negotiable. SOVAT is built with end-to-end encryption, least-privilege access, GDPR-aligned handling, and official QuickBooks integration—so your refunds stay safe from sync to submission.

Encryption in transit & at rest · GDPR-aligned · Read-only QuickBooks scopes · Data minimization · Audit trail & export

Your data, only where it matters

1

Connect (OAuth)

You authorize SOVAT to read the minimum required QuickBooks data. No passwords stored. Revocable at any time.

2

Process (AI + rules engine)

Invoices are parsed and validated against EU rules. Only fields required for refund eligibility are processed.

3

Prepare & submit

We build compliant claims and track them to payout. You review and approve; nothing is filed without your OK.

4

Retain & delete

We keep only what’s needed for compliance and auditing, then purge on schedule or on request. Export or delete anytime.

Privacy by default

Data minimization

We pull only the fields needed to detect eligibility and file claims.

Read-only by default

Integration uses least-privilege, read-only scopes—no ledger changes.

EU-aligned retention

Clear retention windows; deletion on request (right to erasure).

No selling, no ad use

Your data is never sold or used for advertising.

Model safety

Your data is not used to train generic AI models unless you explicitly opt in.

Security you can rely on

End-to-end encryption

All data is encrypted in transit and at rest, following industry best practices.

Controlled access

Only authorized team members have limited, role-based access—and only when needed to support you.

Backups & continuity

Your data is backed up regularly and stored securely for availability and resilience.

Compliance by design

SOVAT is built with GDPR and EU VAT regulations at its core, keeping every claim aligned with the latest standards.

  • GDPR-aligned processing with DPA available on request.
  • EU VAT compliance embedded in the product (local rules, documentation, audit trail).
  • Regulatory updates: we track EU changes (incl. ViDA) and update our rules engine continuously.
  • Sub-processors: a living list published in the Trust Center, with purpose and region for each.
  • Data residency: documented hosting regions and options; cross-border transfers covered by SCCs where required.

Trust Hub

Transparency is the foundation of trust. You’ll find key security and compliance resources here—from our Data Processing Agreement to sub-processor details and system status.

  • System status(coming soon)
  • Security overview (this page summarized)(coming soon)
  • DPA (PDF) and Sub-processor list(coming soon)
  • Change log (security/compliance updates)(coming soon)

Report a security issue

If you believe you’ve found a security or privacy vulnerability in SOVAT, we encourage responsible disclosure. Please contact us at security@sovat.eu. We’ll investigate promptly and keep you informed throughout the process.

security@sovat.eu

FAQ

How does SOVAT stay up to date with changing VAT rules?
Our compliance engine is updated continuously with EU regulations (including ViDA), so filings align with the latest requirements.
Do you store my QuickBooks credentials?
No. We use OAuth; access can be revoked at any time from your QuickBooks account.
Can support see our data?
Only with your explicit approval and time-boxed access for troubleshooting. All access is logged.
Where is our data stored?
We document hosting regions and sub-processors in the Trust Center; data residency options are available depending on plan.
What happens if we leave SOVAT?
You can export your data and request deletion. We honor erasure requests and provide confirmation.

Global standards. Local compliance. Rock-solid security.

SOVAT was built to protect sensitive financial data and keep you compliant—without slowing you down.