Security at Voder
Last updated:
At a glance
VODER reads supported accounting data from Xero, FreshBooks and QuickBooks Online. It does not change accounting records. Separately, an organisation owner can choose optional VODER Actions to create or change supported contacts and invoices in Xero. VODER stores limited account and service data, including encrypted connection tokens, but does not retain financial figures.
No online service can promise zero risk. This page explains the controls Voder uses and the evidence limits that still apply.
Read-only VODER operations
VODER requests read access from Xero and FreshBooks. Intuit grants a broader QuickBooks accounting scope, but VODER limits its QuickBooks operations to reading supported information. VODER does not write accounting records in any of the three services.
VODER fetches only the information needed for the request. It discards the financial figures after returning the requested information to the AI assistant selected by the customer.
Optional VODER Actions for Xero
VODER Actions is separate from read-only VODER. The Xero organisation owner can turn on the complete set of seven contact and invoice actions for that organisation. Individual actions cannot be turned on separately. FreshBooks and QuickBooks Online remain read-only.
VODER Actions can create a contact, correct a contact’s name or email address, create or correct a draft invoice, approve a draft invoice, email an approved invoice, and email an overdue invoice again to chase payment. Approval changes a draft into an approved invoice. Sending an invoice or chasing an overdue one emails the customer. Creating a draft invoice calls Xero immediately after the required checks and does not require confirmation. Each of the other six Actions shows exactly what it will change or send and requires confirmation before VODER sends it to Xero. Before either email, you also see the recipient address.
Turning VODER Actions off removes this organisation’s permission to use those actions in VODER. Xero may still retain the permission previously granted to VODER; review or remove that permission separately in Xero. VODER Actions has no additional VODER charge; existing subscription terms still apply.
Account and organisation access
VODER uses passwordless sign-in. Sign-in codes are stored only as hashes. They are single-use, expire after 15 minutes, and stop working after repeated incorrect attempts.
Before showing or using an organisation, VODER checks that the signed-in account has access to it. Sensitive organisation actions, such as disconnecting an accounting service, are restricted to the organisation owner.
Encryption and hosting
VODER encrypts Xero, FreshBooks and QuickBooks Online connection tokens using AES-256-GCM, a standard encryption method. Each stored token has an encryption key protected by Google Cloud Key Management Service. The service account that runs Voder can use the key. The service account that deploys Voder cannot.
VODER’s primary database and encryption key are in Australia. Its production application service currently runs in Google Cloud’s Singapore region.
What Voder stores and for how long
VODER stores limited account and service records. These include an email address, organisation access records, encrypted Xero, FreshBooks or QuickBooks Online connection tokens, feedback notes you or your AI assistant choose to send, and limited billing records for subscribers. After the assistant records feedback, it tells you what it recorded for the VODER team and why. It stops recording feedback for that conversation if you object. VODER does not store full card numbers.
VODER records whether Actions is on for the organisation. For each attempted action other than creating a draft invoice, it also keeps a code for the request and the organisation and action involved. For an action without a confirmed result, VODER records when it prepared or attempted the request. A confirmed result instead records the Xero record ID and result time. These records do not contain contact names, invoice numbers or invoice line items. Creating a draft invoice calls Xero directly and does not create one of these duplicate-prevention records.
VODER retains and deletes data as follows:
- Hashed sign-in codes are deleted automatically 15 minutes after issue.
- Signed-in sessions expire after 7 days.
- Normal token retention: VODER keeps an encrypted provider token while the connection is available.
- Confirmed token removal: VODER removes provider tokens after a confirmed disconnection or account deletion. Xero paid-access expiry follows the additional lifecycle described in the Privacy Policy.
- If token removal is not confirmed: VODER blocks access and keeps the encrypted token only for a limited retry period.
- Email and account records are deleted when the customer asks Voder to delete the account.
- VODER Actions duplicate-prevention records do not currently expire automatically. The standard account-deletion process does not remove them.
- Feedback is deleted on request.
- Limited billing records may be retained for tax, accounting, fraud, dispute, and legal obligations.
- Technical logs are kept for one year, then automatically deleted. The log store is locked so this period cannot be shortened. Google Cloud’s own audit logs, which record changes to VODER’s infrastructure rather than customer requests, are kept for 400 days (about 13 months).
Read the full retention and deletion schedule in Voder’s Privacy Policy.
Logs
Technical logs record which tool ran, parameter names and lengths, whether the request succeeded, and how long it took. They do not contain parameter values or financial figures from Xero, FreshBooks or QuickBooks Online.
Service providers and AI
VODER relies on a small set of service providers:
- Google Cloud provides application infrastructure and the database.
- Resend sends sign-in email.
- Xero, FreshBooks and Intuit supply accounting data you authorise VODER to read. Xero also processes contact and invoice changes sent through VODER Actions.
- Stripe provides subscription checkout and billing.
- The AI assistant selected by the customer can receive information returned by Voder.
VODER and Windy Road do not train or fine-tune AI models using accounting data from Xero, FreshBooks or QuickBooks Online, or other customer data.
The customer selects the AI assistant. The AI provider handles prompts and information returned by Voder under its own terms, privacy policy, and account settings.
VODER does not sell customer data or share it for advertising.
Security assessment and current limits
Voder completed an internal, self-driven security assessment and penetration test in August 2026. The assessment began in May 2026 and closed with residual findings. Remediation of those findings is ongoing.
This was not an independent or third-party assessment. Voder does not currently claim SOC 2 or ISO 27001 certification, zero risk, or that security incidents cannot happen.
Report a security issue
Email security@voder.ai. Please do not file a public issue for a vulnerability.
Voder aims to:
- Acknowledge a report within 7 calendar days.
- Provide an initial assessment within 14 days.
- Fix confirmed vulnerabilities within 90 days.