Security

Last updated: October 2, 2026

This page answers a practical question: is the client data you type into Incusia locked to your account, and who else can see it? It describes what the product does today.

The connection is encrypted

Incusia is served over HTTPS. A request to http://incusia.com is redirected to https://incusia.com. The production site sends a Strict-Transport-Security header, so browsers keep using HTTPS after the first visit. That covers the marketing site and the signed-in product.

Other customers cannot open your data

The database uses row level security. Each invoice, client, estimate, time entry, and expense is stored with your user id, and the database rules only return rows that match the person who is signed in. That check sits in the database, not only in the page you are looking at. One customer's login does not grant a query against another customer's rows.

Signing in

You sign in with email and password. The password is stored as a hash by Supabase Auth. Incusia does not see the password. A cookie keeps the session. Two-factor authentication is not available.

Card numbers

When a client pays an invoice, or when you pay for an Incusia plan, the card form is Stripe's. Incusia stores a Stripe id so it can show whether something was paid. It does not store the card number.

Who at Incusia can look

Production access to the database and the hosting project is held by the founder, Abass Gass. There is no separate support team with standing access. If you email for help and we need to look at a record to answer, that is the founder looking, and only for that request.

Storage encryption

Data is encrypted at rest by Supabase, Incusia's database provider, as part of their platform. That covers the database and uploaded files. The source is Supabase's published security documentation, which states that all customer data is encrypted at rest. Incusia has not independently verified disk-level encryption. The sub-processor page leaves the database region unnamed, because that region could not be confirmed.

Taking your data with you

Settings has a download for invoices, clients, estimates, time entries, and expenses as CSV, and for invoice and estimate PDFs. It is on every plan, including Free.

Deleting an account

Settings asks you to type your email. After that, the login, clients, estimates, time entries, expenses, activity, logos, and receipts are deleted. Draft invoices are deleted. Issued invoices are kept until 31 December of the year five years after the invoice date, because Norwegian bookkeeping law requires those records, and a monthly job deletes them after that date. An active subscription is canceled immediately. You get a confirmation email. The details are in the Privacy Policy.

Reporting a problem

Email me@abassinvoice.com if you find a security issue. Include what you saw and how to reproduce it. Please do not include a client's full payment details in the email if you can describe the problem without them.

Any questions? Send an email to me@abassinvoice.com and I will get back to you within 24 hours.