Overview
Numinor handles sensitive financial data on behalf of Canadian businesses. Our security program is built around five principles: encrypt everything, grant the least access necessary, monitor continuously, prepare for the worst, and improve after every incident. This page describes how those principles show up in our day-to-day practice.
We would rather this page be specific than reassuring. Where something is not yet in place, it says so, and the sentence is replaced the day it is. The date at the top is the last time somebody read every sentence here against the systems it describes.
Data encryption
In transit. All data moving between your devices, our systems, and integrated platforms is encrypted using TLS 1.3 (or TLS 1.2 where a partner does not yet support 1.3). The Site and the Portal are served over HTTPS only; a plain HTTP request is redirected before anything is sent. The Site also tells your browser to reach it over HTTPS only for the next year, so a later visit never tries a plain connection; the Portal's address ends in .app, a domain browsers already treat as HTTPS-only.
At rest. Client data stored in our systems and at our cloud partners is encrypted using AES-256, with encryption keys managed and rotated by Google Cloud. The credential that lets the Portal read a connected QuickBooks file is held in Google Cloud Secret Manager, one secret per client, and is readable only by the server-side code that needs it — never through the Portal and never from a browser. Only the project's owner account can reach Secret Manager directly.
Backups. Backups are encrypted with the same standards as live data and kept in the same country as the system they protect. What they consist of is under Business continuity.
Access controls
- Sign-in. Nobody has a password to the Portal. Staff and clients sign in through a single-use link emailed to them, so access to the Portal is access to that mailbox — and the Portal account itself is ours to revoke at any time.
- Multi-factor authentication. A second factor for staff sign-in to the Portal is not yet enforced. It is the next item on our security roadmap, and this sentence is replaced the day it is in place.
- Role-based access. A client account can read only its own records, and can never set a status the server owns — an approval, an export, a filing — however the request is made. These limits are enforced in the database's security rules and in the server-side code, not in the screen. Staff accounts see the firm's clients. Access is reviewed quarterly by the firm's principal and revoked the same day an employee leaves.
- An audit trail. Every approval, correction, rejection, reopening, export, connection and disconnection is written to an audit log with who did it and when. The log has exactly one writer in our code, and a test keeps it that way.
Infrastructure
Numinor's systems run on Google Cloud, through Firebase, as managed services: a document database, file storage, serverless functions, hosting, and identity. There are no servers we operate or patch — Google patches the platform — and nothing of ours listens on the open internet except the Site, the Portal, and the functions behind them. Google Cloud holds SOC 2 Type II attestation and publishes its audit reports under non-disclosure to customers.
- Where your data is held. Our systems run in both Canadian and United States regions, and we would rather be specific than reassuring. Your accounting records, review history, messages, audit logs, and the credential for a connected accounting platform are held in Canada (Montreal). Uploaded receipt and document images, and the PDF copy of each monthly report, are held in the United States, as is authentication data such as email addresses. A region is fixed when a system is created rather than chosen per client, so if an engagement requires Canadian-only storage, raise it before signing and we will confirm in writing whether we can meet it.
- Access to the production project is through Google Cloud's identity and access management, with named accounts and the least role each needs. The database and file storage are reachable only through their security rules and our own server-side code.
- Development and testing run against a local emulator and a sandbox accounting file, never against a client's data. Changes reach production through a reviewed pull request and an automated deploy that refuses to report success unless every function it deployed is live.
People and training
Every Numinor team member completes security training during onboarding and again annually. Training covers phishing, secure handling of Client data, password hygiene, and incident reporting. Senior team members and anyone handling Client financial data also receive specialized training on Canadian privacy laws (PIPEDA) and applicable provincial regulations.
Background checks are performed on all employees before they receive access to Client systems. Every team member signs a confidentiality agreement and a data-handling acceptable-use policy as a condition of employment.
Vendor management
We carefully select and review every vendor that touches Client data. Vendors are evaluated against security, privacy, and compliance criteria before onboarding, and reviewed annually thereafter. The vendors that touch Client data are QuickBooks Online and the cloud and processing providers named on our privacy policy: Google Cloud, Anthropic, and Mailgun.
Client portal. Documents and messages you share with us go through the Numinor portal, which we built and operate ourselves rather than hosting on a third-party practice-management platform. It runs on the same cloud infrastructure described above, is invite-only with no public sign-up, and clients sign in through an emailed link rather than a password. Sign in at app1-numinor.web.app.
Automated document processing. Receipts and documents you upload are read by Anthropic’s Claude models, which extract the vendor, date, amounts, and sales-tax breakdown. Anthropic processes this content in the United States, under commercial terms that exclude it from being used to train models. Every extraction is checked by a member of our team before it reaches your books — nothing is filed on a machine’s say-so.
We require data-processing agreements with every vendor that handles Client data, including obligations around encryption, breach notification, and data return on termination.
Incident response
Numinor maintains a documented incident response plan that defines roles, escalation, containment steps for each credential and system we run, and who is notified. Every incident, and every defect found in production, gets a written post-incident review that ends in the rule it produced; those reviews are kept and are how this program improves. The plan is walked as a tabletop exercise at least once a year.
Notification. If a confirmed security incident materially affects your Client data, we will notify affected Clients in writing as soon as practicable, and in any event within the timeframes required by applicable Canadian privacy law (PIPEDA Mandatory Breach Notification within the period prescribed by regulation). Where an incident involves data read from a connected QuickBooks file, we also notify Intuit as its developer terms require.
Data retention and disposal
We retain Client data only as long as necessary to deliver Services, meet legal and regulatory obligations, and complete reasonable backup cycles. Tax-related records are held for seven years from the end of the tax year they relate to, consistent with CRA recordkeeping requirements.
On termination of an engagement, Client data can be returned in standard formats on request. After legal retention periods expire, data is securely deleted from production systems and overwritten from backups according to industry-standard wiping procedures.
Business continuity and disaster recovery
Our systems are managed services, so the failures we plan for are our own — a bad script, a mistaken bulk delete, a purge with the wrong year end — rather than a machine that fails. The database keeps seven days of continuous point-in-time recovery, recoverable to any moment in that window, and cannot be deleted outright without a protection flag being removed first. A full export is taken weekly and kept for ninety days, in the same region as the database. Uploaded files keep thirty days of prior versions, so an overwrite or a deletion is reversible in that window.
Our recovery time objective for core Client-facing services is 24 hours. Our recovery point objective is minutes for the books and review history, and one version for files. Restores are tested rather than assumed: the last tested restore and the next due date are recorded in our operations runbook, and a test is run at least quarterly.
Compliance
Numinor's practices are aligned with Canadian regulatory expectations for handling personal and financial information, including:
- PIPEDA (Personal Information Protection and Electronic Documents Act).
- Applicable provincial privacy legislation, including Quebec Law 25 and Ontario's PHIPA where the engagement involves health-sector clients.
- CPA Canada professional conduct rules and confidentiality obligations.
- CRA recordkeeping and electronic-records requirements.
Our infrastructure partners hold SOC 2 Type II attestation, and we leverage their audit reports as part of our own vendor risk management. Numinor itself does not hold a SOC 2 or ISO 27001 certification.
Report a vulnerability
We welcome reports from security researchers and members of the public. If you believe you have found a security issue in our Site or in our systems, please email us at hello@numinor.ca. Include enough detail for us to reproduce and assess the issue. We will respond within five business days and keep you informed as we work on remediation.
We ask that you do not access or modify data beyond what is necessary to confirm the issue, and that you give us reasonable time to remediate before public disclosure.
Contact
Questions about our security program? Reach out to:
Numinor Accounting · Security
hello@numinor.ca
22 King St S Suite #300, Waterloo, ON N2J 1N8
