Yes. Your receipts, documents, and account data are encrypted both in transit and at rest.
In transit
All traffic between your browser, mobile app, and SparkReceipt's servers is forced over HTTPS with TLS 1.2 or higher, with HSTS preload enabled. There is no unencrypted entry point.
At rest
- Database — the Postgres database that stores your account, documents, and transaction data is encrypted on disk using AES-256.
- File storage — uploaded receipts, invoices, and statement files live in AWS S3 in Stockholm, Sweden, with an encrypted backup in Frankfurt, Germany. S3 server-side encryption is enabled.
- Sensitive credentials — items like email-integration passwords, OAuth tokens for accounting integrations (Xero, QuickBooks), and document share-link passwords get an extra layer of application-level encryption before being written to the database.
What this protects against
Encryption at rest protects against physical access to the underlying disks or backups; encryption in transit protects against eavesdropping on the network. Account passwords are stored as one-way bcrypt hashes — even SparkReceipt staff cannot read them.