Security at Clearsum

Security built for financial work

Accounting firms trust Clearsum with sensitive financial information. We protect it with layered access controls, encrypted integration credentials, private document storage, and safeguards throughout the application lifecycle.

This page is written for technical reviewers evaluating Clearsum.

Your team

Verified identity

Clearsum

Company-scoped workspace

Your ledger

OAuth-authorised

Authenticated session
Company access checks
Encrypted credentials

Security at a glance

Multiple controls, working together

Security does not depend on a single login screen or encryption claim. Each layer has a specific job, from deciding who may enter to protecting provider credentials and recording sensitive activity.

Authenticated access

Protected access starts with a validated user identity, not a shared firm login.

Company-scoped controls

Application and database controls keep access tied to the company a person is authorised to work in.

Encrypted credentials

Connected-provider credentials receive application-level encryption before storage.

Private documents

Receipts and supporting files are kept private and shared through time-limited access links.

Protected connections

HTTPS, origin controls, request validation, and rate limiting protect application traffic.

Secure development

Automated dependency, code, and secret checks run as part of the development lifecycle.

Identity and company access

Access is tied to both a person and a company

Clearsum validates the user session before protected access. Requests are scoped to an active company and checked against that person's membership and permissions.

Database row-level security provides another access boundary, so company separation does not rely only on what the interface chooses to display.

Authorisation in depth

Every layer verifies a different part of access.

  • 1Server-side validation of authenticated sessions
  • 2Active company membership checked before access
  • 3Role-based controls for administrative and sensitive actions
  • 4Database row-level security as an additional boundary
Encrypted in transitServer-side onlyEncrypted before storage

Data and credential protection

Sensitive credentials receive an extra layer of protection

Clearsum encrypts accounting-provider access and refresh credentials before storing them. The keys are maintained outside the database and can be rotated without exposing provider credentials to the browser.

  • AES-256-GCM encryption for stored provider credentials
  • Encryption keys maintained separately from the database
  • Controlled key rotation without exposing credentials to the browser
  • HTTPS for data moving between users, Clearsum, and connected providers

Connected services

Connect without sharing your provider password

Clearsum uses the authorisation flows provided by QuickBooks, Xero, and other supported services. You approve each connection with the provider directly.

Provider-authorised access

Passwords are not shared with Clearsum. Signed, time-limited connection state binds the provider authorisation to the correct person and company.

Credentials stay server-side

Provider credentials are handled by protected backend services and are not exposed through the browser or directly accessible to customer database sessions.

Revocable access

Authorised administrators can disconnect an integration. Clearsum removes its stored connection and requests provider revocation where supported.

Application safeguards

Protection beyond sign-in

Authenticated access is one boundary. Clearsum also applies controls to the traffic, content, and operations that move through the application.

Request protection flow
HTTPS
Origin check
Identity
Company
Validation
Rate limit
1

Transport and browser protection

HTTPS enforcement and restrictive security headers help reduce interception, framing, content-sniffing, and browser injection risks.

2

Request and abuse controls

Structured request validation, exact-origin controls, rate limits, and bounded realtime operations reduce unauthorised or abusive use.

3

Safer content handling

Uploaded files are validated and privately stored. Connected-email content is sanitised before display to remove active or remote content.

4

Restricted production surfaces

Development and diagnostic routes are kept out of production, and sensitive service operations remain behind server-side controls.

Auditability and monitoring

Important activity leaves a record

Clearsum maintains append-only records for bookkeeping-agent actions and security-sensitive administrative events. These records support accountability, troubleshooting, monitoring, and incident investigation.

Actor, company, action, and outcome context
Protected event history for sensitive changes
Monitoring for access denials and unusual activity

Secure development

Security checks are part of delivery

Security is checked while software is being built, not only after release. Automated controls look for vulnerable dependencies, unsafe code patterns, exposed secrets, and risky container contents.

Dependency and static code analysis
Full-history secret scanning
Automated updates and security regression tests

Your controls

Your firm remains in control of access

Administrators can manage company membership and permissions, review important activity, and control connected services. Integrations can be disconnected, and a company owner can delete the company's active data from within the application.

AI control and safety

A separate, equally important question

Platform security explains how information and access are protected. Our Trust & Safety page explains how planning mode, approvals, reversibility, and activity history keep people in control of the AI bookkeeper.

Explore AI control & safety

Technical review

Frequently asked security questions

Straight answers to the questions accounting firms and their technical reviewers ask most often.

Bring us your security questions

Evaluating Clearsum for your firm? We can help your technical or compliance team understand how your data and connected systems are protected.