Your data, and what we do to protect it
You are about to put your customer list, your purchase prices, and your books into someone else's software. That deserves a straight answer rather than a badge wall. Here is what is actually in place — and, at the bottom, what is not.
Controls in place
Tenant isolation in the database
Your data is separated at the database level, not by a filter in application code. Every tenant-scoped table enforces Postgres row-level security against the tenant on the request, so a bug in a query cannot return another business's rows.
Roles, least privilege by default
Owner, admin, manager, staff, viewer, and technician. Sensitive surfaces — party balances, exports, platform settings — are gated to the roles that need them, and a technician is deliberately scoped to their own work rather than the whole business.
Audit log of sensitive actions
Changes to records are recorded with who did it, what changed, and when. Documents that are voided or reversed stay in the trail instead of disappearing. The log is readable in-product on the Pro plan; on other plans it is retained and available on request.
Authentication we do not roll ourselves
Sign-in and sessions are handled by Clerk, a specialist identity provider, so we never see or store your password. Traffic is encrypted in transit.
Managed, backed-up infrastructure
Hosted on Vercel with a managed Neon Postgres database, both of which handle routine backups, patching, and physical security. Errors are monitored so failures surface to us rather than to you.
Data-subject requests, built in
Export or erase an individual customer's or supplier's personal data from the product itself. Erasure anonymises the person while keeping the transactional history your books and tax filings depend on.
What we are not claiming
- No certifications yet. We are not ISO 27001 or SOC 2 certified. We build to the controls those frameworks describe, and we will say so when that changes — not before.
- No penetration-test report to share. We have not commissioned an independent test. If your procurement process needs one, tell us and we will talk about it honestly rather than produce something thin.
- We are a small team. That means fast fixes and a direct line to the people who wrote the code — and it means we do not have a 24/7 security operations centre. Both are true; pick with your eyes open.
Questions we get asked
The binding detail lives in our Data Processing Addendum, Privacy Policy, and Terms. Where this page and those documents differ, those documents govern.
Need this reviewed by your team?
Send us the questionnaire. We answer it ourselves, and we will tell you where the answer is no.