Security
When you run many clients, the bar for trust is high. Isolation, enforced permissions, and an immutable history were part of the design from the start.
Each firm's data is isolated at the database level. Your work is never visible to any other firm. That's how the system is built, not a setting someone can flip.
Bookkeeper, supervisor, accountant, and more. Every action checks the user's role before it runs, so a hidden button is never the only thing standing between someone and data they shouldn't see.
Nothing gets silently rewritten. Each change links cryptographically to the one before it, so an altered record after the fact would break the chain and surface immediately.
A scheduled job re-verifies the chain regularly, so a closed period stays provable months later, when an audit actually asks.
Data is encrypted on the wire and in storage, using current industry-standard protocols.
Bank links are handled through Plaid, so credentials are never stored on our side.
If you believe you've found a security issue, we want to hear about it. Email us at security@ziepie.com with the details and we'll respond promptly. Please give us a reasonable window to investigate and fix before any public disclosure.
We don't hold formal certifications like SOC 2 or ISO 27001 yet. We've built the platform to the practices those standards call for, and we're working toward certification. If your firm needs specific documentation or a security review before that, get in touch and we'll tell you exactly where we are.
Ask us anything. We'd rather be clear up front than leave you wondering.