Encryption everywhere

TLS in transit. AES-256 at rest, with keys managed by Google Cloud. Data is encrypted on every step between your devices, our infrastructure, and our partners.

Least-privilege access

Role-based access enforced in the database, not the screen: a client sees only their own books. Sign-in is by emailed link, never a password. Every approval, correction, export and connection is written to an audit log.

SOC-aligned infrastructure

Hosted on SOC 2 Type II providers. Our partners undergo independent third-party audits annually. Data is held in Canadian and US regions — we say which, below.

Continuous monitoring

Alerts on errors, unscanned uploads and books that fail to reconcile reach us as they happen. Every incident gets a written post-incident review, and the rule it produced.