Security & trust
Your financial data, protected in layers
Every protection on this page is switched on today, for every account on every plan. Here’s exactly what we do to keep your books, your customers’ details and your money safe.
Encryption at rest
Tax numbers, bank details, payment credentials and API tokens are encrypted in the database — 7 sensitive model types, not just passwords.
Tenant isolation
Every request is checked against real business membership before any data loads — enforced at the middleware and policy layer, not just a query filter that could be forgotten.
Two-factor authentication
Available on every account, required for owner/admin roles, with recovery codes for a lost device.
Breach-checked passwords
Every password is checked against known-breached password lists before it is ever accepted — not just a length rule.
Audit trail
Every important action leaves a permanent record.
Issuing an invoice, voiding a document, approving a bill, changing a security setting — each writes an immutable, timestamped event. Nothing is edited after the fact; corrections happen through new, equally-recorded actions, never silent edits to history.
Illustrative activity log
Protected against abuse, not just attack
Rate-limited sensitive actions
Login attempts, password resets, invoice voiding and period locking are all throttled — a compromised session or runaway script can't run wild.
Password re-confirmation for high-risk actions
Voiding an issued invoice, unlocking a closed accounting period, or changing other high-risk settings requires re-entering your password first.
Idempotency-protected payments
Recording a payment is protected against accidental double-submission — a retried request returns the original payment, never a duplicate.