Trust
Built so it cannot lie to you
Trust is not a promise on a slide. It is enforced in the database, in the audit chain and in an export anyone can call. This page says what is live today and what is not, including the places where the honest answer is less than we would like it to be.
The journal
The journal cannot lie
The books are append-only. Nothing is edited and nothing is deleted. A correction is a new reversing entry, so every number keeps its full history and the original stays on the page.
Balance is not a convention we follow. The database itself refuses an entry whose debits and credits disagree and refuses any write into a locked period. Our own code cannot break your books.
The audit log
Every action leaves a chain
Every service writes to one append-only log and every record carries the hash of the record before it. Change any link and every hash after it stops matching, so the log is tamper-evident by construction rather than by policy.
App, worker and public API all write to the same chain. Nothing bypasses it.
Models
What leaves and who reads it
Two providers read two different things and they give two different answers about retention, so both are written here rather than averaged into one comfortable sentence. A photographed receipt goes to Cloudflare Workers AI, which runs inside the same account that already stores the image, so no new company sees the document, nothing is kept outside our own storage and Cloudflare publishes a commitment not to use customer content for training.
A question you type into the chat is the other answer. It goes to OpenAI, which retains request content for a period for abuse monitoring under its standard API terms. We hold no zero-retention agreement with them, so that retention is real and this is the one place the product sends anything to a provider that keeps a copy. Nothing sent there is used for training under those terms. Treat a typed question the way you would treat an email.
What is removed before either call: phone numbers, email addresses, tax ids and long account numbers become placeholders. Party names are matched against your own contact list and replaced, which leaves a real residual: a name your books have never seen. It is named here rather than left to be found. Two more details a reader can act on. The routing call that works out what a question is asking carries the question as you typed it, so a figure you type travels; only the wording call has its figures substituted. And a photograph cannot be masked at all, which is why a receipt is read where it already lives instead.
A model reads and explains. Deterministic math decides.
Export
Your books leave with you
One API request returns the full ledger, the document records and the whole audit history, on any day, with no fee and no waiting period. Two limits, named rather than rounded up: the document files themselves are not in the bundle yet, only the rows that point at them. Fields sealed under your organisation key travel as ciphertext, because key material never leaves.
Lock-in is not a retention strategy we are willing to use. If we stop deserving your books, you take them.
Dated rules
Rules you can check afterwards
A tax rule is a dated row, not a line of code someone changed last spring. When a rate moves the old row stays and the new one starts on its own date.
That is what keeps an old figure defensible. A 2026 transaction is evaluated under 2026 rules however many times the rate has moved since.
Keys and encryption
Where encryption stands today
- Live todayAll traffic runs over TLS and stored data is encrypted at rest by our providers.
- Live todayThe org-key envelope. Each organisation has its own data encryption key and the classified fields are encrypted under it before they reach the database: contact phone numbers, email addresses, tax identifiers, connector refresh tokens and every document in the vault. A leaked table shows ciphertext where those values used to be.
- Live todayRows written before the key existed still read. They re-encrypt the next time they are saved, so nothing had to be migrated in one risky pass.
- On the road mapThe master key that wraps the organisation keys lives in an environment secret, not yet in a managed key service.
- On the road mapOwner-triggered key rotation is designed but not built. Until the managed key service lands, the product runs on fixture and founder-created data only.
We would rather tell you exactly where the line is than round up.
Classified fields sealed under your organisation's own key · never used for training · a photograph or a document is read inside our own account and no copy is kept anywhere else · a question you type into the chat goes to OpenAI, which retains request content for abuse monitoring under its standard terms, with phone numbers, email addresses, tax ids and account numbers replaced by placeholders first · your records export by one API request any day, and the document records come with them while the files themselves are not part of that bundle.