Security

Built so the books are always defensible.

When you run many clients, the bar for trust is high. Isolation, enforced permissions, and an immutable history were part of the design from the start.

Firm-level data isolation

Each firm's data is isolated at the database level. Your work is never visible to any other firm. That's how the system is built, not a setting someone can flip.

Role-based permissions

Bookkeeper, supervisor, accountant, and more. Every action checks the user's role before it runs, so a hidden button is never the only thing standing between someone and data they shouldn't see.

Immutable, hash-chained history

Nothing gets silently rewritten. Each change links cryptographically to the one before it, so an altered record after the fact would break the chain and surface immediately.

Verified every night

A scheduled job re-verifies the chain regularly, so a closed period stays provable months later, when an audit actually asks.

Encryption in transit and at rest

Data is encrypted on the wire and in storage, using current industry-standard protocols.

Bank connections via Plaid

Bank links are handled through Plaid, so credentials are never stored on our side.

Reporting a vulnerability

If you believe you've found a security issue, we want to hear about it. Email us at security@ziepie.com with the details and we'll respond promptly. Please give us a reasonable window to investigate and fix before any public disclosure.

Compliance

We don't hold formal certifications like SOC 2 or ISO 27001 yet. We've built the platform to the practices those standards call for, and we're working toward certification. If your firm needs specific documentation or a security review before that, get in touch and we'll tell you exactly where we are.

Questions about how we handle your data?

Ask us anything. We'd rather be clear up front than leave you wondering.