Security & Trust

Built on a foundation of trust.

Virexa handles your invoices, receipts and tax data. We protect them like a Finnish bank would — with EU hosting, strong encryption, and per-user data isolation.

EU data residency

All data is stored in European data centers. Your data never leaves the EU.

Encrypted in transit & at rest

TLS 1.3 in transit, AES-256 at rest. Backups are encrypted with the same standards.

Row-Level Security

Every row in our database is scoped to your account. Other users physically cannot read your data.

Secure authentication

Email + password with hashed credentials, plus optional Google sign-in via OAuth 2.0.

GDPR compliant

Export or delete all of your data with a single click. We act as a data processor under the GDPR.

AI transparency

AI providers process prompts only — your data is never used to train models. Each request is logged for auditability.

What data we collect

We store the information you create inside Virexa: invoices, customers, receipts, mileage entries, and the chat history with the AI tax helper. We also store the minimum account data required to sign you in (email, hashed password) and basic usage metrics.

What we never do

We don't sell your data. We don't share it with advertisers. We don't use your invoices, receipts or chat history to train AI models. AI providers process individual requests on your behalf and discard them after.

Your rights under GDPR

You can export all of your data as JSON/CSV at any time, request a full deletion that removes every row tied to your account, or contact us at support@virexainvoice.com for any GDPR request.

Reporting a vulnerability

We welcome responsible disclosure. Email support@virexainvoice.com with details and a way to reproduce. We respond within 72 hours.