Security & Compliance
List your team's SaaS tools (one per line with monthly cost); get a spend audit that flags duplicate categories, forgotten tools, and a suggested savings number. For SMB ops and finance managers tracking tool sprawl.
What we handle
Tool names and monthly costs you submit (your SaaS inventory), plus team size and org context used to estimate savings. We do NOT ask for bank, card, or login credentials, and do not connect to your billing provider unless you explicitly configure a read-only integration. We do not train public models on your submissions without explicit consent.
Data handling commitments
- Input is used only to generate your spend report (GDPR Art.5 — data minimization).
- We minimize retained data and avoid storing secrets longer than needed.
- Transfers use standard encryption in transit (TLS) (GDPR Art.32 — security of processing).
- Access is restricted to the account that submitted the data.
Compliance posture
GDPR: lawful basis is contract / legitimate interest for processing your own submitted business data (Art.6). We support data deletion on request (right to erasure, Art.17). We are not a certified auditor or financial advisor.
Subprocessors
We rely on our hosting provider (Vercel) and payment processor (Waffo). No data is sold to third parties (OWASP Top 10 — secure defaults).