Security
Your books are sensitive. Our job is keeping them that way.
Security claims are cheap; mechanisms are not. Everything below describes how this service actually works — no badges, no borrowed certifications, just the practices in place today.
Encrypted in transit, hashed at rest
Everything between your browser and our servers travels over encrypted connections. Passwords are never stored — only irreversible hashes — so nobody inside or outside the company can read them.
Sessions you can revoke
Sign-ins use signed, expiring session tokens. Change your password and every other session is signed out instantly — stolen logins die with the password.
Access limited to your named team
Only the bookkeeper and specialists assigned to your account can see your numbers. Roles are enforced server-side on every request, not hidden in the interface.
Privileged actions are audited
Logins, failed logins, data exports, and account changes are written to an internal audit trail — who did what, from where, and when.
Abuse protection on every public form
Lead forms, the AI assistant, newsletter signups, and sign-in are all rate-limited, with duplicate-submission protection so your inbox and ours stay clean.
Your data stays yours
We don't sell or share your financial data with third parties. Export everything at any time; deletion happens on request. Unsubscribe links are cryptographically signed so nobody can opt an address out but you.
Questions about a specific practice? Ask on your free consultation — we'll walk through it with your actual account. For how we handle personal data legally, read our privacy policy.