Security
Principles first, claims later
These are the security principles Bobby Receipts is being designed around. They describe intent, not a verified implementation.
Bobby Receipts is under development. Security architecture and operational controls will be verified before pilot use.
Design principles
What the product is being built to protect
Private by default
Documents are intended to be private to the workspace they were uploaded into, and visible only to the people that workspace includes.
Workspace separation
Separation between workspaces is a design requirement: a personal workspace and a company workspace must never see each other's documents.
Role-based access
The direction is that what a person can see, change and approve follows their role in the workspace.
Controlled approval history
Approval decisions are intended to be recorded as history rather than silently overwritten.
Auditability
Being able to answer 'what happened to this document, and who did it' is a stated product requirement.
Secure provider connections
When mailbox and storage connections are built in later phases, they are intended to request the narrowest access that works, and to be revocable.
Export and deletion controls
Getting your documents out, and having them deleted, are product requirements rather than optional extras.
Data minimization
The intent is to hold what the workflow needs and no more.
Your documents are not a product to sell
Selling the contents of your receipts is not part of the product plan.
Explicit non-claims
What Bobby Receipts does not claim
- No encryption claim is made here, because no storage architecture has been verified yet.
- No certification is claimed: not SOC 2, not ISO 27001, and no audit has taken place.
- No regulatory compliance status is claimed, in any jurisdiction.
- No security testing result is claimed, because none has been performed and published.
- The product is not production-ready and is not offered for real document handling.