Documentation
1. Getting started
- Create an account with your email address and a password of at least 12 characters.
- Name your organisation. Everything you upload belongs to the organisation, and other organisations can never see it.
- Upload a few invoices and review them.
2. Uploading documents
Accepted: PDF, JPEG, PNG and WebP, up to 10 MB per file. The file type is checked from the file's contents, not its name. Uploading the same file twice returns the existing document instead of creating a copy.
After upload a document is Queued, then Reading, which usually takes under a minute. If the AI provider is briefly unavailable, Invoice Review retries automatically with increasing delays. If a document cannot be read, it is marked Failed with the reason, and you can try again.
3. Reviewing: confidence, checks and escalation
For each document Invoice Review records these fields, each as printed on the document or "not on document": document type, supplier, supplier address, supplier VAT ID, supplier IBAN, customer, invoice number, issue date, due date, currency, net total, VAT total, gross total, payment reference, plus the VAT breakdown and line items.
Confidence is the AI model's own estimate, per field, that the value is exactly what the document says. It is shown so you know where to look first. It is not a guarantee.
Checks are calculated by Invoice Review, not by the AI:
| Check | Fails when |
|---|---|
| Required fields | Supplier, issue date, currency or gross total is missing (and the invoice number, for invoices and credit notes) |
| Totals add up | Net + VAT differs from gross by more than 0.01 |
| VAT lines sum | The VAT breakdown does not add up to the VAT total |
| VAT rate arithmetic | A line's VAT differs from net × rate by more than 0.02 or 0.5%, whichever is larger |
| Line items sum | Line amounts add up to neither the net nor the gross total (±0.02) |
| Dates | A date is not a real calendar date, the issue date is in the future, or the due date is before the issue date |
| Currency | The currency code is not one Invoice Review recognises |
| VAT ID format | The VAT ID does not match its country's format. This is a format check only; it is not checked against the EU VIES register. |
| IBAN | The IBAN's check digits are wrong |
| Confidence threshold | Any field with a value is below the confidence threshold (90%) |
| Unreadable content | The model reported something present but illegible, cut off or contradictory |
If any check fails, the document goes to Needs review with the reasons listed. Otherwise it is Ready to approve.
Correcting: edit any field and save. Your values are stored as a new version (the model's original reading is kept) and all checks run again. Approving: the approved values are frozen and become exportable. A document in Needs review can only be approved after you tick that you have checked its issues. Rejecting requires a reason.
4. Bank statements and matching
Import a statement as CSV. Invoice Review finds the header row by itself (account details above the table are skipped) and recognises common English, German and French column names: for example Date/Buchungstag, Amount/Betrag, Debit+Credit/Soll+Haben, Reference/Verwendungszweck, Payee/Empfänger, Currency/Währung, IBAN. Comma, semicolon and tab separators, decimal commas, and dates like 12.09.2026, 12/09/2026 (read day first) and 2026-09-12 are supported. If a row can't be read, nothing is imported and the row number is shown.
Matching uses approved documents only. Supplier invoices and receipts are matched to outgoing payments, and credit notes to incoming ones. The payment must fall between 10 days before the issue date and 90 days after the due date.
| Result | When |
|---|---|
| Exact | Same amount, and the reference contains the invoice number or payment reference, or the IBAN matches, or the counterparty name matches the supplier |
| Partial | Same amount but nothing else confirms it; or within 2% with a confirming reference, IBAN or name (a bank fee or discount); or a matching reference with a different amount |
All proposed matches, exact or partial, wait for you to confirm or reject. A rejected pairing is not proposed again.
5. Exports
Exports contain approved documents only, optionally filtered by issue date. Every export is written to the audit log. Cells that begin with =, +, - or @ (other than plain numbers) are prefixed with an apostrophe so spreadsheet programs do not run them as formulas.
| Format | Columns |
|---|---|
| CSV | document_id, file, type, supplier, supplier_vat_id, supplier_iban, invoice_number, issue_date, due_date, currency, net_total, tax_total, gross_total, vat_breakdown, payment_reference, approved_at |
| Xero bills | *ContactName, *InvoiceNumber, Reference, *InvoiceDate, *DueDate, *Description, *Quantity, *UnitAmount, *AccountCode, *TaxType, TaxAmount, Currency. One line per document at its net amount. |
| QuickBooks Online bills | Bill No., Supplier, Bill Date, Due Date, Memo, Account, Line Description, Line Amount, Line Tax Code, Line Tax Amount, Currency. One line per document at its net amount. |
For Xero and QuickBooks you enter an account code and a tax code that already exist in your own setup, and choose the date format your organisation uses. These layouts follow the vendors' published bill-import fields. Test with a small file first: accounting software differs by country and plan, and suppliers may need to exist before import.
6. The audit log
Each event records who did what, to which document, and when. Each event's seal is an HMAC-SHA256 over the previous event's seal and the event's own contents, using a secret key held only by the Invoice Review service. The service also records the latest event separately.
Every time the audit page is opened, the whole chain is recomputed. It reports a problem, and the first event affected, if an event was edited, if an event was inserted or deleted, or if the newest events were removed. In the database, audit rows cannot be updated at all, and they can only be deleted by the organisation-erasure procedure.
What it does not prove: someone who has both full database access and the service's secret key could rewrite the log consistently. The log protects against changes made without the key. It is not a public or third-party timestamp.
7. Organisations and roles
The person who creates an organisation is its owner. Every member can upload, review, approve, match and export. Only the owner can erase the organisation. Row-level security in the database separates organisations as well as the application code: each request can only read and write rows of the organisation the signed-in user belongs to.
8. Erasing your data
In Settings, the owner can erase the organisation. This permanently deletes all its documents, readings, corrections, bank transactions, matches, audit events and memberships, in one database transaction. It does not touch any other organisation. User accounts are not deleted, because a person may belong to other organisations. Invoice Review keeps a record that an erasure happened, holding a one-way hash of the organisation's identifier and the number of rows removed, and no content. Nightly backups made before the erasure are deleted automatically after 14 days.
9. Data location and processing
See Where your data goes and the privacy notice. In short: storage is in Frankfurt, Germany (Alibaba Cloud, eu-central-1). Documents are read by Anthropic's Claude model through Amazon Bedrock's European inference profile (eu.anthropic.*), called from AWS Frankfurt (eu-central-1). The service refuses to start if it is configured for any non-European model endpoint. There is no GCC hosting at present.
10. Limits
| Limit | Value |
|---|---|
| File size | 10 MB per document; 2 MB per bank statement; 10,000 statement rows |
| Uploads | 20 per minute per user |
| API requests | 120 per minute per user |
| Sign-in attempts | 5 per minute |
| Password | 12 to 128 characters |