Your numbers, handled the way a CFO would.
We hold some of the most sensitive data a business has. Here's exactly how we protect it.
You never share a password
Connecting Xero uses Xero's own OAuth consent. We receive a scoped, revocable token — never your Xero login — and only the permissions shown on the consent screen. Disconnect at any time from settings or from within Xero, and all future access stops.
Encrypted in transit and at rest
Your data is encrypted on the wire and in storage. Access is role-restricted per workspace, so people only see the entities they've been given access to.
Payroll stays private
Employee names and pay detail are masked by default and sit behind a PIN the account owner sets. Sensitive payroll is kept out of AI processing and off default screens, and access to employee data is logged.
Reconciled to the cent
Every sync runs a bank-reconciliation self-check: each account is anchored to its Xero balance and non-bank movements are excluded, so a quietly-wrong forecast surfaces itself instead of misleading you.
Australian-region hosting
The app runs on Vercel with data hosted on Supabase (PostgreSQL and file storage), using processing regions close to Australia where available. Each processor only receives what it needs for its function.
We never see your card
Billing is handled by Stripe, a PCI-DSS Level 1 provider. Card numbers go straight to Stripe — they never touch our servers.
Your data is yours
You can export or correct your information, disconnect Xero, or delete an entity or your whole account at any time. We don't sell personal information and we don't train AI models on your business data.
Breach notification
No system is perfectly secure. If a breach is likely to cause serious harm, we notify affected users and the OAIC as required by Australia's Notifiable Data Breaches scheme.
Full detail lives in our Privacy Policy and Terms of Service. Security questions? Get in touch.