Bank-grade encryption, by default
Your financial data is among the most sensitive you have. So we encrypt every sensitive field with a key that's unique to your business — no setup, no add-on fee.
How your data is protected
A private key per business
Each business's data is encrypted with its own AES-256 key, wrapped by a master key. No business can ever touch another's data.
Encrypted in transit & at rest
TLS 1.3 on every connection, plus disk-level and field-level encryption for stored data.
Three encryption levels
From a master key, to a per-business key, to per-field derived keys — you choose the level that fits.
Crypto-shredding
Delete a business's key and its data becomes instantly unrecoverable — right-to-erasure (PDPL/GDPR) in one click.
Tamper-evident audit log
Every financial change is written to an immutable log — and its snapshots are encrypted too.
Strict tenant isolation
Every query is scoped to your business at the database layer, and automatically tested on every release.
Transparency is part of security
Field-level encryption covers what identifies your customers: contact names, emails, phones, tax numbers, addresses and notes; invoice, bill and credit-note notes and line descriptions; payment references; bank transaction narratives; e-invoicing credentials; and the audit log. Amounts, dates and statuses stay queryable so the accounting engine and reports can work — protected by disk encryption and strict tenant isolation — and so does descriptive metadata such as account names and manual journal memos.
All of it for $99 a year