One login, one set of jobs
Each client login can only see the jobs and files it uploaded. The check runs on our server on every request, not just in the page.
Your statements are sensitive. Here is how we protect them, in plain English, and what we don't claim.
Statements are sensitive financial data. We treat them that way.
Each client login can only see the jobs and files it uploaded. The check runs on our server on every request, not just in the page.
Our team sees only what's needed to do your books. Your profile stays editable only by you, and staff views of it are logged.
Logins, uploads, downloads, approvals and changes are recorded with who and when.
Use an authenticator app for a 6-digit code at login, with single-use backup codes. Required for every Our team member; available to every client.
Repeated wrong passwords lock the account for a while, and sign-in attempts are rate-limited.
You confirm your email before uploading, and finished files are only ever sent to that verified address as login-protected links.
Passwords are stored only as strong one-way hashes (argon2id). Two-step secrets are encrypted at rest.
Uploaded files are kept in private storage, never on a public web folder, and every download checks who you are first.
The client portal is built to run only over encrypted HTTPS connections.
In-house bookkeeping, no outsourcing.
Your statements are reviewed by our own North American team. We never hand them to an outsourced data-entry shop.
We don't hold SOC 2, ISO 27001 or similar certifications today, and we'll say so here if that changes. No system is 100% hack-proof; we follow well-established security practices and keep improving them. Questions? Ask us.
Ask in chat or contact us. A human will answer.