How Noverbill protects your freight data
Carrier invoices, contract rate cards and dispute correspondence are commercially sensitive. This page explains the controls that govern who can reach that data inside Noverbill, where it is processed, and how long it is kept.
Last updated August 2026 · Maintained by Noverbill Technologies Inc.
Scope and shared responsibility
This page describes the security controls in place for the Noverbill application and how responsibility is divided between us, our infrastructure providers and you.
- Noverbill operates the audit application, its access rules, its data model and its integrations.
- Our infrastructure providers operate the underlying hosting, managed database, authentication and object storage services.
- Your team manages who is invited into your workspace, the strength of account credentials, and the documents you choose to upload.
Authentication and access control
- Every workspace surface behind sign-in requires an authenticated account session.
- Accounts are created through email and password or Google sign-in; sessions are issued and refreshed by the managed authentication service.
- Password resets are delivered by email as single-use, time-limited links that are consumed the first time they are opened.
- Platform administration is a separate role held in a dedicated roles table; it cannot be self-assigned from the application.
Tenant isolation
Invoices, rate cards, company records and representative profiles are scoped to a single company. Isolation is enforced in the database itself with row-level security, not only in application code, so a request can only read or write rows belonging to the company the signed-in user is attached to.
- Uploaded files are stored in private buckets partitioned by company identifier.
- Document links are issued as short-lived signed URLs rather than public URLs.
- A representative cannot move themselves between companies; reassignment is restricted to platform administrators.
Data handling in the audit pipeline
- Uploaded carrier invoices are parsed with a vision model to extract invoice numbers, BOL references, lanes, line items, currency and totals.
- Extracted values are audited against your rate card terms, checked for duplicate billing, and compared against published Bank of Canada reference exchange rates for cross-border currency spread.
- Audit results, extracted fields and the source document remain in your workspace.
- Invoice content is sent to our AI processing provider only for the purpose of extraction and is not used by Noverbill to train models.
Encryption and network
The application, its API calls, file uploads and signed document links are served over HTTPS (TLS). Data at rest is stored on managed database and object storage services that provide storage-level encryption. Service credentials and API keys are held as server-side secrets and are never exposed to the browser.
Subprocessors and integrations
Noverbill relies on the following categories of providers to deliver the service:
- Managed application hosting and serverless execution.
- Managed PostgreSQL database, authentication and object storage.
- AI document extraction for invoice parsing.
- Transactional email delivery for account and recovery messages.
- Mapping and geocoding to visualise origin and destination lanes.
- Bank of Canada Valet, a public reference source for historical exchange rates.
A named list of current subprocessors is available on request for customers under contract.
Retention, deletion and portability
- Workspace data is retained for as long as the account is active.
- Invoices and rate cards can be deleted from within the workspace by an authorised representative of that company.
- On written request we will delete or export a workspace's remaining data, subject to records we must keep for legal or accounting reasons.
Reporting a vulnerability or incident
If you believe you have found a security issue, email contact@noverbill.com with steps to reproduce. Please do not test against other customers' data or attempt to degrade the service. We will acknowledge reports and keep the reporter informed of remediation. If an incident affects your data, we will notify affected workspace administrators by email.
About certifications
This page is app-owner maintained documentation of the controls in place today. It is not an independent audit, attestation or certification. Where a formal framework is required for your procurement process, contact us to discuss current status and available documentation before relying on any specific claim.
Questions, requests or disclosures
Write to contact@noverbill.com or submit a clearance request and note your question in the message.
Contact Noverbill