Home / Security

Security

Quick Payable is built natively on Salesforce, so your invoices, approvals, vendor records, and users are stored and managed inside your own Salesforce organization rather than in a separate AP database. This page covers how security works as a result, and what your Salesforce administrator controls directly.

Salesforce-Native Architecture

Because Quick Payable data lives in your Salesforce org, it's covered by your organization's existing Salesforce security model rather than a separate one Quick Payable maintains independently. That includes Salesforce's authentication, permissions, data access controls, and secure transmission (Salesforce uses SSL/TLS for browser connections to the platform). There's no separate Quick Payable login or database to secure on top of what your Salesforce admin already manages.

User Access: QP Admin and QP Staff

Access to Quick Payable is controlled through Salesforce users, permission sets, profiles, and Quick Payable's own user configuration. Quick Payable supports two application roles:

RoleTypical Access
QP AdminAdministration, configuration, approvals setup, vendors, and integrations
QP StaffDay-to-day accounts payable activities, based on the permissions assigned to them

Assign access based on each user's actual responsibilities, and give users only what they need. See Assign Permission Sets and Licenses.

Authentication and Session Security

Users sign in to Quick Payable through their existing Salesforce login, and are subject to whatever authentication and session policies your Salesforce administrator has configured, including multi-factor authentication (MFA), session timeout, and login IP restrictions. There's no separate Quick Payable password to manage.

Data Access Controls

Because Quick Payable records are standard Salesforce records, they're covered by Salesforce's normal access control layers: profiles, permission sets, object permissions, field-level security, and record-level sharing. Use field-level security to restrict sensitive fields, such as vendor banking details, to only the roles that need them. See Administration.

Invoice and Document Security

Invoice records and their attached files (PDFs, scans) are stored using standard Salesforce platform storage, and inherit the same access controls as any other Salesforce record and file. If your organization needs encryption at rest beyond Salesforce's platform defaults, for particularly sensitive fields or attachments, Salesforce Shield Platform Encryption can provide this where supported by your Salesforce edition. Shield is a separate Salesforce product and license, it is not included automatically with every Salesforce org.

Email Invoice Processing Security

When email-based invoice capture is configured (see Connect Your Invoice Inbox), the Email Service can be restricted to accept mail only from specific sender domains using the Accept Email From setting. We recommend:

  • Restricting accepted senders to your known vendor domains where practical, rather than leaving the address open to any sender.
  • Not publishing the invoice inbox address publicly, since an unpublished address is harder to target with unwanted mail.
  • Reviewing your Email Service configuration periodically, particularly the Accept Email From list, as vendors change.
  • Enabling Error Routing so a specific administrator sees processing failures rather than the sender.

Approval Routing Controls

Approval routing is configured through the Users tab in Quick Payable, not a generic Salesforce Approval Process. Each user can be configured with:

  • QP Admin or QP Staff role
  • Profile
  • Monetary Approval Limit
  • Manager
  • Active status

When an invoice amount exceeds a user's Monetary Approval Limit, it routes automatically to that user's configured Manager. This gives you an application-level control over who can approve what, on top of standard Salesforce permissions. See Set Up Approval Routing.

AppExchange Distribution

Quick Payable is distributed as a managed package through Salesforce AppExchange. Salesforce requires managed packages to pass a security review before publication, covering the package's code, integrations, and any external services it uses. During installation, Salesforce will prompt you to approve access to the specific third-party services Quick Payable requires; review and approve only what's needed for the features you're using.

Administrator Responsibilities

Security here is shared: Quick Payable provides the application, and your Salesforce administrator configures and maintains access within your org. We recommend:

  1. Give users only the QP Admin or QP Staff access they need, not more.
  2. Review user access, Monetary Approval Limits, and Managers on a regular schedule.
  3. Deactivate access immediately when someone leaves or changes roles.
  4. Restrict invoice email senders to trusted domains.
  5. Use MFA and your organization's standard Salesforce security policies.
  6. Review Salesforce login and security activity as part of your normal security procedures.

Questions about a specific security requirement?