Security and Your Data in an AI Bookkeeping Platform
Last reviewed 11 July 2026

In short
Your data is encrypted at rest, accounts support two-factor authentication, and access follows role-based control with a full audit trail. Email connections are read-only with one-click disconnect, external AI agents get only scoped revocable tokens, and we operate under UK GDPR. We make no certification claims — we describe controls and invite questions.
Bookkeeping data is intimate: who pays you, what you spend, where the margins are. If we want it, we owe you a plain description of how we protect it. This page is that description — controls stated specifically, limits stated honestly, and no badge-collecting.
The basics, done properly
Encryption at rest. Your data — ledger, documents, account records — is encrypted where it is stored. Your original source documents are retained so every entry can always be traced back to its evidence.
Two-factor authentication. Accounts support 2FA, and we encourage every user to enable it. A password alone is a poor lock on a door this important; the NCSC's Small Business Guide gives the same advice for a reason.
Role-based access control. Access inside the platform follows roles: people see and do what their role requires, and nothing more. A reviewer working your books has reviewer permissions; administrative capabilities are separated; your own team members can be given appropriately narrow access. Least privilege is the default posture, not an upgrade.
An audit trail throughout. Changes to your books are recorded — every AI draft, every human edit, every approval, with who and when. The trail exists for accounting integrity first, but it doubles as a security property: unusual activity has nowhere to hide in a system where actions are attributable by design.
Email access: read-only, revocable, yours
Connecting your email lets the platform collect invoices and receipts as they arrive. That connection is deliberately minimal:
- It uses the official Gmail and Microsoft APIs with read-only scopes. The platform cannot send from your mailbox, delete messages, or alter anything.
- We never see or store your email password. Authorisation is a token you grant to us, held by us — not credentials typed into a third party.
- Disconnection is one click, in your settings, effective immediately. No support ticket, no retention of access.
AI-specific boundaries
An AI platform has attack surfaces a traditional one does not, and we design for them explicitly.
Documents are treated as untrusted input. Anything ingested — PDFs, emails, photos — is data, never instructions. Extraction output is confined to a structured draft that must pass AgentLedger's deterministic validation and then human approval. Text hidden in a malicious invoice can, at worst, produce a bad draft that a validator and a person will inspect; there is no path from document content to executed action, and no path from AI output to money moving.
External AI agents get scoped, revocable access. Agents connect over MCP using OAuth 2.1 tokens carrying explicit, least-privilege scopes. No external agent can post to your ledger — the most any agent can do is read what its scopes allow and propose drafts that enter the same validation-and-approval pipeline as everything else. Every call is logged, and every grant is visible and revocable by you.
UK GDPR
We operate under UK data protection law and take its obligations as design requirements rather than paperwork: a lawful basis for processing, data used for the purposes we state, and your rights honoured — access, correction, erasure where it applies, and portability. Portability, in particular, is real here rather than theoretical: your books are kept as a plain-text ledger and your original documents are retained, so leaving with a complete, usable record is something the architecture supports, not something it grudges. The ICO's UK GDPR guidance is the authoritative public reference if you want to check our obligations against our behaviour.
What we will not claim
You will notice this page names no certifications. That is deliberate: we do not make certification claims we cannot substantiate, and we would rather describe the actual controls — encryption at rest, 2FA, RBAC, read-only integrations, scoped tokens, audit trails — than decorate the page with acronyms. Security is also never finished, and no honest provider will tell you a breach is impossible. What we offer instead is specificity, a genuinely small attack surface around the AI, and a standing invitation: if your accountant or technical adviser has questions about any control described here, ask us the hard version at [email protected].
Want this handled for you — with a person accountable for it?
Check eligibility / Ask for DetailsNo payment on the first step. No free trial.