Listra
Trust Center

Built for sensitive financial workflows.

Listra processes invoices, payment data, vendor information, and contract terms. This page is the current state of our security and compliance program: what is live, what is underway, and exactly how each control works. When something is in progress, we say so.

SOC 2 Type IIAudit underway
HIPAACompliance underway
AES-256 encryptionAt rest and in transit
SSO and MFASAML 2.0, required
GDPR and DPAAvailable on request
AWS infrastructureUS-based and hardened
Trust at a glance

Compliance, infrastructure, access, and assurance in one view.

The controls that finance and IT leaders want to verify before signing a security questionnaire, with honest status on each: live today, underway, or on the roadmap.

Compliance

SOC 2 Type II In progress
HIPAA In progress
DPA and GDPR Available
SOX-ready audit trail Live
EU data residency Roadmap

Infrastructure

AES-256 at rest Live
TLS 1.2+ in transit Live
AWS KMS rotation Live
Point-in-time backup Live

Identity and access

SAML 2.0 SSO Live
SCIM provisioning Live
MFA on high-value Required
Thirty RBAC categories Live

Testing and assurance

Internal penetration testing Complete
Third-party penetration test Underway
Continuous monitoring Live
Incident reporting policy Live
Tenant isolation

Your data does not touch any other customer's.

Isolation is enforced at every layer, not bolted on at the application level. Listra's reasoning on a given invoice draws only on that customer's data, integrations, and policies.

Every layer enforces isolation independently. A failure at one layer is caught by the next. Customer A's reasoning never sees Customer B's data.

API gateway Auth-scoped
Database schema Tenant-keyed
Query layer Row-level enforced
AI reasoning Customer scope only
No shared data path Enforced independently at every layer above.
AI governance

Clear boundaries on what the AI does with your data.

Finance and IT leaders are right to ask what an AI vendor will not do with their data. The boundaries below are not optional. They are how the platform was built.

No training on your data

Customer data is not used to train models that serve other customers.

No cross-customer reasoning

Listra's reasoning on your invoice draws only on your data and policy.

No data sale or sharing

Your data is never sold or shared with third parties for any commercial purpose.

No unbounded posting

No autonomous GL posting outside the policy and thresholds you configure.

The detail

How each control works.

Full detail is available in our security questionnaire and DPA. The summaries below cover what most finance and IT teams ask first.

Encryption

AES-256 at rest. TLS 1.2 or higher in transit. Keys managed via AWS KMS with documented rotation policies.

Cloud architecture

AWS infrastructure with network segmentation, hardened images, and continuous monitoring. Multi-tenant with company-level isolation at the API, database, and query layers.

Backup and recovery

Continuous backups with point-in-time recovery. RPO and RTO targets defined per tier. Detail in the security questionnaire.

Identity provisioning

SAML 2.0 SSO via your identity provider. SCIM automates provisioning and de-provisioning where supported.

Role-based access

Thirty permission categories with action-level granularity. Pre-built roles for AP Specialist, AP Manager, Controller, CFO, and Admin. Full customization available.

Human-in-the-loop default

Listra ships in Copilot mode for every exception type. Autopilot is enabled per exception type only after you review accuracy data and authorize the change.

Penetration testing

Internal penetration testing is complete and recurring. An independent third-party penetration test is underway.

Incident response

A documented incident reporting policy covers detection, response, and customer notification. Available on request via the Trust Center contact.

Certifications underway

The SOC 2 Type II audit and HIPAA compliance program are both in progress. Reports will be available under NDA as each completes.

Documentation

Get what your security review needs.

Security questionnaires, our DPA, and the incident reporting policy are available on request. The SOC 2 Type II report will be available under NDA once the audit completes. Contact security@listra.ai.