63ef82b759379b22e4b1fe21_image 129-1
645368d8beeb4e7e190fb7d0_trademark

Announcements

Published on August 5, 2025

Welcome to our brand-new Trust & Security Portal, a single place to access all our policies, compliance documents, audit reports, and security practices. We created this space to keep our customers informed, confident, and secure.

 

Compliance

Documentation of our compliance against global standards including certifications, attestations, and audit reports.

general-active-logo.fc2e36cff8509b820b4f
general-active-logo.fc2e36cff8509b820b4f
Download Doucments

Security:

Policies:

Download Doucments

Continuous monitoring

App Security

Penetration Test

Code ReviewProcess

Vulnerability Assessment

Secure SDLC

Vulnerability Management

Web Application Firewalls.

Data Security

Data Backups

Data Encryption

Data Governance

SSL/TLS Enforcement

Strict Access Control Policy

Infrastructure Security

Baseline Security Setup on our Cloud.

Encryption at rest

Password Policy

24/7 SOC Monitoring

Malware detection & EDR

Automated Patching

Network Security

Firewall

Logging and Monitoring

24/7 SOC Monitoring

Organization Security

Acceptable Usage Policy

Code of Conduct

Disaster Recovery Plan

Incident Response Plan

Dedicated Security Team

Security Awareness and Training

Subprocessors

aws.amazon-_1_

Amazon Web Services

Cloud computing services including Infrastructure as a Service (IaaS) and Platform as a Service (PaaS) offering.

Location: US
gemini.google

Google

Artificial intelligence research and deployment, including AI models like Gemini
Location: US
azure.microsoft

Azure OpenAI

Artificial intelligence research and deployment, including AI models like GPT (Generative Pre-trained Transformer),

Location: US
stripe

Stripe

Stripe provides billing, subscription, and invoicing services.

Location: US
www.anthropic

Anthropic

Artificial intelligence research and deployment, including AI models like Claude

Location: US

Frequently Asked Questions

Detailed, plain-language answers to the questions security, procurement, and privacy teams ask us most before signing off on Discover Dollar.

What is the Discover Dollar Trust & Security Portal, and why does it exist?

This portal is Discover Dollar's single source of truth for how we protect the accounts payable and financial data our customers upload to Shield — the certifications we hold, the policies we operate under, and the controls we run day to day, all in one place instead of scattered across emails and one-off security questionnaires.

We publish it because our platform ingests sensitive AP data (invoices, purchase orders, contracts, emails, payment records) to detect overpayments, so procurement, security, IT, and legal teams evaluating us as a vendor need fast, verifiable answers before they trust us with that data. Every certificate, audit report, and policy linked above is the primary source of record; this FAQ section explains what they mean and how they fit together, it doesn't replace them.

What certifications does Discover Dollar hold, and what does each one actually certify?

We hold three independent certifications or attestations, each covering a different layer of assurance:

  • SOC 2 Type II — an AICPA attestation confirming our controls were designed and operated effectively over an observation period, not just documented on paper.
  • ISO/IEC 27001:2022 — certifies we run a documented Information Security Management System (risk assessments, control ownership, continuous improvement), audited by an accredited certification body.
  • ISO/IEC 42001:2023 — a newer standard specific to AI management systems, covering how we govern, test, and monitor the AI models built into our product.

We also publish a GDPR assessment report and a redacted VAPT (penetration test) report. Downloadable copies of all of these are in the Security section above.

I need a document that isn't listed here — a security questionnaire, an unredacted VAPT report, or something under NDA. How do I get it?

Everything we can share publicly is already linked in the Security and Policies sections above. For anything more sensitive — a full-detail penetration test report, responses to a custom vendor security questionnaire, or a document that requires a mutual NDA before we can share it — email privacy@discoverdollar.com with your company name and what you need. Our security team reviews these requests individually rather than through a self-serve form, since some documents can only go out once an NDA is on file.

How does Discover Dollar actually protect the data I upload, beyond a general promise to "take security seriously"?

Protection happens at four layers, all listed under Continuous Monitoring above:

  • Application: a Secure SDLC, code review, regular penetration testing and vulnerability assessments, and web application firewalls.
  • Data: encryption at rest, SSL/TLS enforced in transit, defined data governance rules, and regular backups.
  • Infrastructure: a hardened cloud baseline, 24/7 SOC monitoring, malware detection and EDR, and automated patching.
  • Organization: least-privilege and Zero Trust access under a Strict Access Control Policy, enforced with a password policy, a dedicated security team, and mandatory security-awareness training.

No single control is the whole story — it's the combination, reviewed continuously, that we publish above.

Discover Dollar's product uses AI — what does that mean for the safety of my company's financial data?

Our AI-driven overpayment detection draws on models from more than one provider — Anthropic's Claude, Google's Gemini, and GPT via Azure OpenAI — selected by task rather than depending on a single vendor. Each is contractually bound as a subprocessor (see below) and processes only the data needed for the specific analysis requested; none is authorized to use customer data to train its own foundation models under our agreements.

How we build, test, and monitor these AI features — including human review points and model risk management — is governed by our Responsible AI Use Policy. Our ISO/IEC 42001:2023 certification specifically audits this AI governance process, not just our general infrastructure.

Who are Discover Dollar's subprocessors, and why does each one have access to data?

We use five subprocessors today, each doing one specific job, all located in the US: Amazon Web Services hosts our infrastructure (IaaS/PaaS); Google's Gemini and Azure OpenAI's GPT models power parts of our AI analysis; Anthropic's Claude powers another part of it; and Stripe handles billing, subscriptions, and invoicing only — it never touches your AP data.

We keep this list current on this page rather than only inside a contract exhibit, and we update it whenever a subprocessor is added, removed, or changed. Check the Announcements section at the top of this page for the latest change log.

How long does Discover Dollar keep my company's data, and what happens after I stop being a customer?

Retention timelines and secure-deletion procedures for each category of data we hold are defined in our Data Retention Policy, downloadable in the Policies section above — we don't keep data longer than necessary to deliver the service, meet contractual commitments, or satisfy a legal or regulatory retention requirement.

If you have a specific question about your account — for example, exactly what happens to your data after contract termination — that's best answered against your specific agreement, so reach out to privacy@discoverdollar.com and we'll walk through it with you directly.

What happens if Discover Dollar has a security incident or data breach?

We run a two-part process. Our Incident Response Policy defines how our security team detects, triages, contains, and remediates an incident internally, including escalation paths and a post-incident review. Our Breach Notification Procedure defines who we tell, how fast, and through what channel if an incident is confirmed to involve customer data, aligned to the notification obligations in the regulations that apply to that data.

Both documents are downloadable above. In short: we don't wait for a scheduled audit to find out something went wrong, and we don't stay quiet if it affects you.

Is Discover Dollar GDPR compliant, and what rights do I have over my data?

Yes. Our GDPR assessment report, available in the Security section above, documents our compliance posture against the regulation. Our Privacy Policy explains, in plain language, what personal data we collect, why, the legal bases we rely on, and the rights available to data subjects — including access, correction, deletion, portability, and objection, depending on your jurisdiction.

To exercise any of those rights or ask a GDPR-specific question, email privacy@discoverdollar.com; we handle these directly rather than through a generic support queue.

How often does Discover Dollar test its own security, and can I see the results?

Security testing is continuous, not annual box-checking: we run regular vulnerability assessments and penetration tests, supported by ongoing vulnerability management and a Secure SDLC that catches issues before code ships, plus web application firewalls that catch what testing might miss once code is live.

Our most recent VAPT report is published in redacted form in the Security section above — redacted so it documents our findings and remediation without publishing an exploit roadmap to anyone browsing this page. A fuller version can be discussed under NDA (see the question above on requesting additional documents).

Who inside Discover Dollar can actually see or touch customer data?

Access is restricted by our Strict Access Control Policy, built on least-privilege (you get access to exactly what your role requires, nothing more) and Zero Trust (access is verified continuously, not assumed because a device or user is "inside the network").

That's reinforced structurally: a dedicated security team owns access governance, a company-wide Password Policy sets authentication standards, and every employee — not just engineers — goes through security awareness and compliance training as a condition of employment, backed by our Code of Conduct and Acceptable Usage Policy.

What's Discover Dollar's plan if there's an outage, natural disaster, or other major disruption?

We maintain two related but distinct plans: a Business Continuity Plan, covering how the organization keeps operating — people, processes, communication — through a disruption, and a Disaster Recovery Plan, covering how our technical systems and data specifically get restored.

Both sit alongside a formal risk assessment framework that identifies what could go wrong before it does, so continuity planning isn't theoretical. The Business Continuity Plan is downloadable in the Compliance section above; ask your account contact if you need specifics for a vendor risk review.

How often is this Trust & Security Portal updated, and how do I know if something changed?

We update this page whenever something material changes — a certification is renewed or added, a policy is revised, or our subprocessor list changes — rather than on a fixed schedule, so what you're reading reflects our current posture, not a snapshot from whenever we last remembered to check.

The Announcements section at the top of this page is where we log those updates. If you're relying on this page for an ongoing vendor review, it's worth bookmarking the live page rather than saving a static copy.

I have a security or privacy question that isn't answered here — who do I actually talk to?

For anything privacy-related — data subject requests, GDPR questions, or clarifications on our Privacy Policy — email privacy@discoverdollar.com directly.

For security questionnaires, deeper technical due diligence, or documents that require an NDA, route through your Discover Dollar account contact, who will loop in our security team — that way requests tied to an active commercial relationship get the context (timeline, contract) they need to be answered properly, rather than sitting in a generic inbox.

Additional Details:

Trust Through Transparency. Security by Design.

At Discover Dollar, security and privacy aren’t features - they’re foundations.
We build with Security by Design and Privacy by Default, ensuring every product decision prioritizes risk mitigation, transparency, and global compliance from day one.

Our commitment includes:

  • Regular security reviews and third-party audits

  • Transparent policies for customers and regulators

  • Modern principles like Zero Trust and least privilege

  • Company-wide security awareness and compliance training

In today’s digital world, trust is currency and we earn it every day.

Privacy Details

Privacy Details:

For Privacy related information please follow the link: Discover Dollar Privacy Policy Or Contact: privacy@discoverdollar.com