Safe AI at collects.io: how every decision is made, and where you stay in control
2026-09-24
collects.io combines a rules engine, an AI layer and a person who owns every exception. Here is exactly how a decision moves from your ledger to your customer's inbox.
Six steps, every time
- Your Xero ledger: a read-only connection. We read invoices, contacts, credit terms and payments. We never write to your ledger.
- Your mailbox: we match the emails about invoices on your ledger, such as replies, remittances and disputes, to the right invoice. What we keep, and for how long, is in our privacy policy.
- The AI proposes: it works out why each invoice is unpaid and what to do next.
- The rules engine applies: your rules decide what happens, and every message must clear seven send controls, in order.
- A person decides the exceptions: anything above set confidence or risk thresholds comes to your team, and the day-90 formal notice always waits for an owner or admin.
- Sent from your own mailbox: your customers hear from you, and every email traces back to the decision and the invoice behind it.
Seven send controls, checked in this order
- Global stop
- Customer pause
- Rule pause
- Frequency cap
- Weekends and UK bank holidays
- Do Not Disturb
- Opt-out
Controls at four levels
- Your organisation: sending limits from day one. No emails are sent at weekends, or on UK bank holidays if you switch this on.
- Each customer: Do Not Disturb stops every invoice for that customer, with your reason logged.
- Each invoice: pause with a logged reason. Disputes, promises to pay and payment plans hold reminders on their own.
- Escalation: reviews at day 14 and day 60; at day 90 the formal notice waits for an owner or admin to approve it.
How your data is protected
- Every action is written to an append-only log that cannot be edited, not even by our own service accounts.
- The database, file storage and our AI run in the UK on Supabase (UK) and AWS London (eu-west-2). Supporting services are listed on our sub-processor page.
- Row-level security on every customer table, so one organisation cannot read another's data.
- Our models learn only from synthetic invoices we generate ourselves, never from your ledger.
- Working towards ISO 27001, ISO 9001 and ISO 42001, target Q1 2027. Not yet certified.
The full method is in our security paper on the Safe AI & Security page.