Everything your reviewer will ask for
Maintained by Apex Flow Technology Ltd. These are the operator's own statements about how SwiftInvoicePro is built and run — self-authored, dated, and deliberately explicit about what we do not hold. Nothing here is a third-party audit or certification.
Documents
Draft Art. 28 processor agreement for the 60-day read-only pilot: scope and duration, categories of data, read-only processing instructions, security measures, sub-processors, EU SCCs and the UK IDTA where applicable, breach notification, DSAR assistance, audit rights, and deletion on termination. Marked DRAFT for your legal review. Readable in full here, with a PDF for your legal team.
CycloneDX 1.5 SBOM generated from the committed lockfile — every runtime dependency, its resolved version, artefact hash, and declared licence, with the source commit recorded in the document metadata. Generated, not hand-written, so it cannot drift from what is deployed. Because it lists exact dependency versions, it is shared on request rather than published, and you always receive the current build.
A signed statement of what we hold, what we do not, why, and the trigger and timeline for a SOC 2 Type 1 engagement. Written for the reviewer who has to explain an uncertified vendor internally.
Every CAIQ Lite domain answered Yes / No / N/A with a one-line note, marked self-assessed and dated — published in full so your review can start today rather than after an email exchange. Where the answer is No, the reason is stated. We will also complete your own CAIQ, SIG Lite, or internal form within five business days.
Inherited infrastructure assurance
SwiftInvoicePro runs on Cloudflare's edge network with managed PostgreSQL in AWS EU-West (Ireland), and uses Stripe for payments. Cloudflare holds SOC 2 Type II and ISO 27001; Supabase and the underlying AWS platform hold SOC 2 and ISO 27001; Stripe is PCI DSS Level 1 and no card PAN reaches our systems.
The limit of that claim: those certifications cover the providers' platforms. They do not extend to the SwiftInvoicePro application layer, and Apex Flow Technology Ltd does not claim them as its own. Apex Flow Technology Ltd is not SOC 2, ISO 27001, or PCI DSS certified and holds no completed third-party penetration test. The bridge letter sets out the trigger and timeline for closing that.
Independent security testing
No third-party penetration test has been completed to date, and none is claimed. What is in place today, and what happens next, is set out below.
Database access-control and policy scanning, and a dependency vulnerability scan of every runtime component in the committed lockfile, both run against the deployed build.
Latest run 8 September 2026 — no known dependency vulnerabilities at any severity; no unresolved access-control findings.
Your own security team, or a testing firm you retain, is welcome to test the application. An isolated environment seeded with synthetic hotel data is live, alongside a written scope covering the public endpoints, tenant isolation, authentication, role checks and webhook signing, and a named contact for the duration of the test.
Open the testing environment and scopeRequest an engagement key
Commitment: a full penetration test by an independent CREST-accredited firm will be completed before any production go-live, and the summary report shared with you. It is not a prerequisite for the 60-day pilot, which is read-only, uses no production credentials of ours, and writes nothing back to your PMS.
Sub-processors
| Sub-processor | Purpose | Region |
|---|---|---|
| Cloudflare, Inc. | Edge hosting, DNS, TLS termination | Global edge |
| Supabase (via Lovable Cloud) | Managed Postgres, authentication, storage | EU-West (Ireland) |
| Stripe Payments Europe, Ltd. | Payment processing | EU / Global |
| Resend | Transactional email delivery | EU / US |