How We Handle Your Data
An honest account of our current security practices — not a list of certifications we don't yet hold.
Where We Stand Today
We're a growing company, and we'd rather be direct about our current security posture than list certifications we don't hold yet. Here's where we actually stand:
- Every client engagement is NDA-backed before any data is shared
- Your financial data stays in your own QuickBooks Online, Xero, or other accounting software — not a separate proprietary system you'd lose access to
- We are actively working toward formal certification (SOC 2) — we'll tell you exactly where we are in that process if you ask, rather than claiming it's already complete
- Access to client systems is limited to the team members actually working on your account
What This Means Practically
Because we work inside your own accounting platform rather than a separate system, your data benefits from that platform's own security infrastructure (QuickBooks Online and Xero both invest heavily in this) in addition to our access controls and confidentiality practices.
Questions We Expect
If you're evaluating us for vendor security review, we'd expect you to ask about our certification timeline, access control practices, and incident response plan specifically. We'll answer directly rather than pointing to generic marketing language.
Have Specific Security Questions?
Ask us directly — we'd rather answer honestly than guess what you want to hear.
