Skip to main content

Security

Your books are sensitive. Our job is keeping them that way.

Security claims are cheap; mechanisms are not. Everything below describes how this service actually works — no badges, no borrowed certifications, just the practices in place today.

Encrypted in transit, hashed at rest

Everything between your browser and our servers travels over encrypted connections. Passwords are never stored — only irreversible hashes — so nobody inside or outside the company can read them.

Sessions you can revoke

Sign-ins use signed, expiring session tokens. Change your password and every other session is signed out instantly — stolen logins die with the password.

Access limited to your named team

Only the bookkeeper and specialists assigned to your account can see your numbers. Roles are enforced server-side on every request, not hidden in the interface.

Privileged actions are audited

Logins, failed logins, data exports, and account changes are written to an internal audit trail — who did what, from where, and when.

Abuse protection on every public form

Lead forms, the AI assistant, newsletter signups, and sign-in are all rate-limited, with duplicate-submission protection so your inbox and ours stay clean.

Your data stays yours

We don't sell or share your financial data with third parties. Export everything at any time; deletion happens on request. Unsubscribe links are cryptographically signed so nobody can opt an address out but you.

Questions about a specific practice? Ask on your free consultation — we'll walk through it with your actual account. For how we handle personal data legally, read our privacy policy.