netcaseai™
  • Security
  • Terms
  • Privacy
  • Free Trial →

Security at Netcase AI

Last updated: August 7, 2026

Netcase AI is operated by Advanta Systems, LLC in Washington State. This overview explains how we protect the financial information you and your clients place in the platform.

Questions or a vendor security questionnaire? Contact support@advantasystems.ai.

The short version

  • Your data is yours. We do not sell it, use it for advertising, or use it to train an AI model.
  • Customer data is access-controlled. Every request involving a company, statement, loan, or forecast is authenticated and scoped to the owning user.
  • Data is encrypted in transit and at rest on enterprise US cloud infrastructure.
  • Production data is backed up through independent providers, and the restore process has been tested end to end.
  • Security is an ongoing discipline. Automated scanners, documented threat reviews, and security checks are part of the development process.

Infrastructure and encryption

LayerProviderProtection
Application hostingVercel ProServerless application hosting over HTTPS
DatabaseSupabase managed PostgreSQLUS-hosted, encrypted at rest, no anonymous public table access
AuthenticationClerkDedicated identity and session infrastructure
PaymentsStripeNetcase never stores full payment-card numbers
AI processingAnthropicUsed only when an enabled AI feature is requested
Off-site backupsCloudflare R2Encrypted and separate from the database provider

All production traffic is served over HTTPS with HSTS. Application secrets are stored in encrypted hosting-environment settings, never in source code. QuickBooks and Xero connection tokens are encrypted separately with AES-256-GCM.

Account security and access control

  • Authentication is handled by Clerk; Netcase does not see or store your password.
  • Session cookies are HTTP-only and same-site restricted.
  • Every customer-data query is filtered by the owning user's identity. A request for data you do not own returns not found rather than another customer's record.
  • Sign-up includes bot and abuse protection.
  • Support access is restricted to the platform owner, uses a short-lived attributable token, and displays a persistent impersonation banner. We contact customers before accessing an account unless they have asked us to investigate something.

Financial data and AI

Financial statements, spreadsheets, PDFs, loan details, forecasts, and notes are stored inside your account. When you intentionally use document extraction, analyst chat, or narrative generation, the relevant information is sent to Anthropic to perform that request.

Two commitments govern that processing:

  1. Customer data is not used to train foundation models, and Netcase does not train its own model on customer data.
  2. AI can be disabled. When AI is disabled, the server prevents that account from sending requests to the AI provider. Core statements, forecasts, ratios, spreadsheet imports, and reports continue to work.

AI-proposed model changes are presented for review. They do not silently alter a forecast, and potentially broad work can be performed in a cloned case so the base case remains untouched.

Application safeguards

  • An enforced Content Security Policy and additional browser-security headers protect the production application.
  • Upload and data-entry routes use input validation plus file-size, file-count, payload, and PDF-page limits.
  • User and AI text is escaped rather than inserted as executable HTML.
  • Billing, authentication, and integration webhooks are cryptographically signature-verified.
  • Sentry captures application failures with automatic secret scrubbing; document-upload request bodies are excluded so uploaded financial content does not enter error monitoring.
  • Dependency auditing, static security analysis, and dynamic application scanning are run and reviewed as part of ongoing maintenance.

Backups and recovery

Netcase uses a three-layer recovery strategy:

  1. Daily managed database backups with seven-day retention.
  2. Nightly encrypted off-vendor database backups in Cloudflare R2 with 30-day retention.
  3. Encrypted backup of production configuration and credentials.

The full restore process was tested on July 22, 2026 by decrypting a nightly backup, restoring it into a clean database, and reconciling the restored tables and row counts.

Your control over your data

  • Export: Statements, forecasts, and reports can be exported at any time.
  • Deletion: Account deletion removes customer records from production systems; residual encrypted copies expire under the backup-retention windows.
  • Access and correction: Contact support@advantasystems.ai.
  • Privacy choices: See the Privacy Policy for the complete description of collection, processing, retention, and individual rights.

What we do not claim

We believe direct disclosure is more useful than vague assurances:

  • Netcase AI is not currently SOC 2 certified. The controls described here are real and documented, but they have not been attested by a third-party SOC auditor.
  • No independent third-party penetration test has been completed yet. Current testing includes automated dependency, static, and dynamic scanning plus structured code reviews.
  • Netcase AI is not a system of record. Keep authoritative accounting records in your accounting platform.
  • No internet-connected system is perfectly secure. We use layered controls, tested recovery, and an incident-response process, and we will notify affected customers as required by law if an incident occurs.

Security questions: support@advantasystems.ai

netcaseai™
  • Security
  • Privacy
  • Terms
  • Contact

© 2026 Advanta Systems, LLC