Trust Center
What We Actually Do, and What We Don't Yet
Security pages usually list adjectives. This one lists what is actually in place — and states plainly where we have controls, where we have intent, and where we have neither.
Isolation
Every company's records are kept separate at the foundation of the system, across 200+ kinds of record, not by a filter the software has to remember to apply.
Most systems that host many companies keep them apart by adding a company filter to every request for data, which works until one request forgets. Here the separation is built into the foundation: a session working in one company cannot see another’s records even if it asks for them, because the rule sits beneath the request rather than inside it.
Integrity
History is never overwritten. Every record is sealed to the one before it, and a correction is a new entry that reverses the old one, so the original stays in the books.
The books' tamper-evident seal is re-checked automatically on a schedule, and a break raises an alert rather than waiting to be discovered during an audit.
Every pack you issue is recorded with a unique seal, so you can say exactly what you sent, when, and prove it has not changed since.
Those three together answer the question an auditor actually asks: not “can this be edited?” but “would you know if it had been?” The seal makes tampering detectable, the scheduled check means it is detected without anyone thinking to look, and the issuance register means what you sent someone is a matter of record rather than of memory.
An independent timestamp authority attests that a package existed on the date it claims. The recipient checks that attestation with standard tools, against a certificate fetched from the authority rather than from us — so the last step of the proof rests on someone we do not control.
That last one is what closes the gap the other three leave open. Everything above is still our system checking itself, however well it does it. A timestamp signed by an authority we do not control is the one piece of the proof that does not depend on us at all — the recipient checks it with standard tools, against a certificate they fetch from that authority rather than from us.
Access
Two layers of permissions: a firm-level role, plus a per-company set that governs what each person can see and approve.
Two-factor authentication and passkeys are built in, not an upsell tier.
Permissions are per company, not global — someone who prepares for one client and approves for another has exactly those rights in exactly those places. Approval thresholds are configurable by amount, and the person who created a transaction is not the person who can approve it.
Data Ownership
Your data exports whenever you ask — statements, ledgers, trial balance, journals — because books you cannot take with you are not really yours.
A complete due-diligence package, with statements, ledgers, agings and evidence, produced as a snapshot of one moment in time and carrying a seal anyone can check.
There is no export tier and no retention hostage-taking. The same process that builds a diligence package for a bank builds one for you on your way out.
Our Data Processing Addendum sets out what we do with your data as your processor, in the terms a procurement review expects: where it is hosted, who else touches it, how a security incident is notified, and how your data is returned or deleted when you leave.
Certification: Where We Actually Are
SOC 2: not started
We do not hold a SOC 2 report, we are not in an observation window, and we have not engaged an auditor. We intend to pursue SOC 2, and we are not attaching a date to that intention — a date given before an auditor is engaged is a guess, and you would be right to hold us to it.
What exists in the meantime are the controls described on this page: each company’s records kept separate at the foundation, a ledger whose history is never overwritten and is sealed against tampering, scheduled checks of that seal, and a register of every document we have issued. Those are things you can test in the sandbox rather than assertions you have to accept.
If your procurement process requires a current SOC 2 report as a gate, we will not clear it today, and we would rather you learn that here than three weeks into an evaluation.
Questions This Page Didn’t Answer
Security reviews always have a question the published page missed. Send it to contact@automate-accounting.com and you will get a straight answer, including when the answer is “not yet”. The ledger page covers how the ledger protects itself in more depth.
