Security
Security and data handling
Written for the person at your firm who has to sign off on a new tool. What the controls actually are, and which questions we would rather answer for you specifically.
Access is denied by default
There is no public sign-up. Staff are invited by a firm admin and authenticate with Google, and a person without an invitation is refused rather than given a reduced view. For a system holding client financial records, an open registration form is a liability, so the product does not have one.
Roles are distinct rather than cosmetic. A platform admin operates the hosted service and manages firm tenants. A firm admin manages that firm's clients, staff, and settings. A bookkeeper works the clients they are assigned to. A client portal user reaches their own uploads and questions and nothing else.
Separation is enforced in the query, not the interface
A bookkeeper assigned to six clients cannot reach the other forty-four, because the membership filter is applied when data is loaded rather than by hiding controls from someone who could otherwise request the record directly. Hiding a button is not access control, and a product that relies on it fails the first time somebody edits a URL.
The same principle governs integrations. QuickBooks Online is authorised per client company rather than once for the firm, so a credential cannot reach a client it was not issued for.
Integration credentials are encrypted at rest
Tokens for connected services, including QuickBooks Online and Plaid, are encrypted before they are stored rather than held in plain text in the database. Platform secrets are managed through the admin interface, and revealing one is itself recorded as an audited action, so a credential cannot be read quietly.
The record shows what happened
Ledger edits are versioned at field level with the previous value retained, so a change to a vendor, a category, or a business-use percentage can be shown rather than reconstructed from memory. Platform activity is written to an audit log with the acting user, the action, the affected entity, and a timestamp.
This matters beyond security. When a firm is asked months later to justify a figure, the difference between a defensible answer and an awkward one is usually whether the system recorded who changed what.
Limits on what automation can do
Runs produce drafts and nothing else. No automated process approves a line, files a return, or sends anything to a client. Approval is a human action, so the blast radius of a bad extraction is a draft a reviewer corrects.
Per-client monthly run caps and a global suspend control bound execution. Automation that can be triggered repeatedly should have a ceiling, and a misconfigured folder should produce a stopped run rather than an open-ended cost.
Your obligations do not transfer
Under PIPEDA, a firm that hands personal information to a service provider remains accountable for it. Veridbooks is a processor in that relationship, not a way to move responsibility, and any vendor implying otherwise is worth treating with suspicion.
Practically, that means your engagement letters and client consents still need to cover the tools you use, and your own retention obligations still apply to the records you keep here.
Questions we would rather answer directly
Some due-diligence questions deserve a specific answer for your firm rather than a marketing paragraph: where data is hosted, which sub-processors are involved in document processing, how long data is retained after an engagement ends, and what happens to your records if you leave.
Ask us during onboarding and we will answer them in writing. A generic reassurance on a web page is not something a firm should accept as diligence, so we are not offering one here.
Common questions
- Can a bookkeeper see clients they are not assigned to?
- No. Access is scoped by membership and applied when data is loaded, not by hiding interface elements.
- Are QuickBooks and Plaid tokens stored in plain text?
- No. Integration credentials are encrypted before storage, and revealing a stored platform secret in the admin interface is recorded as an audited action.
- Can Veridbooks file or send anything without a person approving it?
- No. Runs only create drafts. Approval is a human action, and nothing reaches QuickBooks Online or a client until a staff member approves it.
- Where is our data hosted, and who processes documents?
- We answer hosting location, sub-processors, and retention specifically during onboarding, in writing. Those are diligence questions that deserve a precise answer rather than a generic statement on a marketing page.
- Does using Veridbooks affect our PIPEDA obligations?
- Your firm remains accountable for personal information it hands to a processor. Using Veridbooks does not transfer that accountability, and your engagement letters and client consents should reflect the tools you use.
See also the privacy policy and terms of use.
Send us your diligence questions
If your firm has a security questionnaire, send it over. We would rather answer it properly than have you guess from a web page.
