You own the data you enter
Your ledgers, customers, suppliers, stock, employees and documents belong to your business. We hold them to run the service for you, and for no other purpose.
Your accounting system holds your customer list, your margins, your payroll and your tax position. This page describes the controls that protect it, in enough detail to be checked — and is explicit about the questions we answer in writing rather than on a web page.
Every control below can be demonstrated in a live system during your evaluation.
This is the first thing to settle with any cloud vendor, because everything else depends on it.
Your ledgers, customers, suppliers, stock, employees and documents belong to your business. We hold them to run the service for you, and for no other purpose.
Export to Excel, CSV and PDF is built into every report rather than being a paid extra or a support request. You are never holding your own history hostage to a subscription.
The business records inside a customer’s workspace are not used for advertising, not resold, and not used to build products for anyone else.
Each organisation’s data is held in its own workspace, separate from every other customer’s. Users authenticate into your organisation and see only its records.
User activity logging records actions taken in your workspace, and the accounting audit trail records every posting and every correction with the user and reason attached.
If your subscription ends there is an agreed wind-down period in which you export your records. The terms of that are set out in the service agreement, not decided at the time.
Most real-world losses are not sophisticated attacks. They are an ex-employee whose login still worked, or a member of staff who could reach something they should never have been able to reach.
Least privilege is worth the setup time. The most common configuration mistake we see is one powerful role shared by everyone, because it was quicker on day one. We will push back on that during implementation — segregation of duties is the control auditors test first.
Security is usually discussed as keeping people out. For an accounting system the harder problem is making sure that what is inside cannot be altered without trace.
A posted invoice, receipt, payment, stock voucher or ledger entry cannot be edited in place. There is no administrative route around this, and that is the point.
A mistake is fixed with a credit note, debit note or reversing journal that references the original document, and records the approving user and the stated reason.
Checkout, night audit, online payments and stock issues each carry a safe-retry reference, so repeating a failed action returns the document that already exists instead of creating a second one.
Stage-based setup checks block posting until ledgers, tax terms, numbering and mappings are correct, so misconfiguration is caught before it produces a period of wrong entries.
Any figure in any report drills back through to the documents that produced it, which is what makes an audit a review rather than a reconstruction.
Both automatic and manual backup and restore are part of the platform. Ask us to demonstrate a restore during your evaluation rather than taking the word for it.
Security pages are full of phrases like "bank-grade encryption" and "99.9% uptime" that mean nothing without the detail behind them. We would rather answer these properly, to your procurement team, in a document we can be held to.
A note on how to read any vendor’s security page. If a claim has no scope, no date and no way to verify it, it is decoration. Ask for the questionnaire, ask who signed it, and ask when it was last reviewed — of us and of everyone else you are considering.
If your organisation has a vendor assessment process, send it. We would rather work through your questionnaire than have you infer answers from a web page.
Procurement and IT questions are answered by the team responsible, not by sales.