Security & Data Handling

You're putting client financials into a new tool. Here's exactly what happens to them.

Written in plain language, not marketing copy. If you're an advisor with a professional reputation attached to this decision, you should be able to read how it works and judge for yourself.

Encrypted everywhere

Encrypted in transit and at rest across every storage layer. OAuth credentials get an additional layer of application-level encryption and are never stored in plaintext.

Isolated per client

Every client gets their own dedicated data warehouse. Isolation is enforced at three independent layers, so one client can never reach another's data.

Never used for AI training

Under our AI provider's commercial API terms, inputs and outputs are never used for model training. Your data is not sold, shared, or repurposed.

Where your data is stored, and how it's encrypted

Different types of data are separated deliberately rather than pooled into one store.

  • Encrypted in transit and at rest across every storage layer, without exception.
  • Financial data lives in a dedicated data warehouse provisioned per client - not in a shared table with a tenant column.
  • Application data is stored separately from financial data, including dashboard configuration and chat history.
  • Raw source payloads are archived with per-client partitioned paths.
  • Third-party OAuth credentials - like your accounting software tokens - receive an additional layer of encryption at the application level and are never stored in plaintext.

Can one client ever see another client's data?

No. Isolation is enforced at three independent layers, so a failure at any one layer doesn't expose anything.

  • Database layer. Every query is scoped to the authenticated user's permitted accounts.
  • Data warehouse layer. Each client has their own isolated dataset. AI-generated queries are read-only and cannot reference any other client's data.
  • Application layer. Tenant identity is determined server-side, and any client-supplied identifiers are stripped to prevent spoofing.

What actually gets sent to the AI

This is the question most advisors want answered, and the answer is narrower than people assume.

  • AI features are powered via a commercial API called server-side directly from our backend. No third-party intermediaries are involved.
  • When a question is asked, only that question and the specific, row-capped query results needed to answer it are sent to the model.
  • Your full dataset is never bulk-exported to the AI.

On accuracy: the AI analyst answers from connected client data only - it isn't drawing on general knowledge or inventing figures from outside the books. It's built for the routine "what happened and why" questions, not to replace professional judgment. You control what's published to a client, and you see the same dashboard they do.

Is my data used to train AI models?

No.

  • Under our AI provider's commercial API terms, inputs and outputs are never used for model training.
  • Data sent to the API is retained for approximately 7 days for trust-and-safety monitoring only, then deleted. It is not retained for any other purpose.
  • Our AI provider operates strictly as a data sub-processor. Your data is not sold or shared.

Access control on your side

You decide what a client sees and when they see it.

  • Nothing reaches a client until you publish it. No client receives an invite you didn't send.
  • Role-based access. Viewer and Admin roles let you separate who can see a dashboard from who can change one.
  • Test on the demo client first. A pre-loaded example account lets you evaluate everything before connecting a real book.

Still have a question?

If your firm has a security review process or a client with specific requirements, get in touch and we'll work through it directly rather than pointing you at a PDF. See also our Privacy Policy and End User License Agreement.

Try it on the demo client first

A fully loaded example account is waiting when you sign up. Evaluate the whole thing before you connect a single real book. No credit card, nothing bills automatically.

Start for Free

Have a security question first? Get in touch or book 15 minutes.