Security

Ask us the diligence questions

Short answers, and where to check them yourself once you're in.

Every company is its own tenant

Data is scoped to the workspace it belongs to, on every read and every write. Switching between companies is an explicit switch, not a filter on a shared pile.

Access comes from a membership or an engagement

A person sees a company's books because they were invited to that company, or because that company accepted their firm. Remove the membership, or end the engagement, and the access goes.

Roles are separate from plans

What someone is allowed to do and what the subscription includes are two different checks, and both have to pass. A client viewer can't reach the internal pages regardless of plan.

The audit trail records who did what

Every change is attributed and timestamped. History is kept for at least as long as your jurisdiction requires records to be kept — your plan can extend that window and cannot shorten it.

Closed periods are locked

A posted entry in a closed period can't be edited. It can be reversed, in an open period, on the record.

Sign in with Google, a password, or a one-time link

Passwords live in Firebase Authentication, never in this application. A new password account confirms its address before any books are opened on it.

Check it from the inside

The sample business workspace has the same access model as a real one. Open it, change a role, close a period, and read the audit trail it leaves behind.