## TL;DR

Invoices carry bank details, tax IDs, and personal data that need protection beyond ordinary documents. Classify fields at extraction, encrypt sensitive fields at rest, mask them in UIs and logs, and restrict access by role. Treat the extracted data store with the same care as the ERP itself.

## Steps

1. Classify extracted fields by sensitivity at extraction time.
   Expected: A labeled data model.
2. Encrypt bank details and tax IDs at rest.
   Expected: Protected storage.
3. Mask sensitive fields in review UIs and logs.
   Expected: Least exposure.
4. Restrict access by role.
   Expected: Need-to-know enforcement.
5. Purge per retention policy.
   Expected: No indefinite hoarding.

## When to use

- AP data protection
- Review UI design
- Compliance (GDPR, etc.)

## When not to use

- Network security
- ERP access control
- Fraud detection

## Compatibility

Framework-agnostic.

## Variant phrasings

### invoice PII protection

### bank details masking AP

### tax ID encryption invoices

## Root cause

AP pipelines copy sensitive data into logs, queues, and analytics stores where it was never meant to live. Classification at extraction contains the spread.

## Edge cases

- LLM prompts must not include unmasked PII; mask before sending
- Backups inherit the encryption requirements
- Vendor portals need the same masking as internal UIs

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_8mLnZA3EMpKtloScvNaAnQ
