Session and account controls
ficary uses signed server-side session cookies, guarded app routes, and password confirmation for destructive account deletion.
Security
ficary is built around scoped access, encrypted financial tokens, audit evidence, and operational checks that make launch blockers visible before they become customer problems.
ficary uses signed server-side session cookies, guarded app routes, and password confirmation for destructive account deletion.
Sensitive provider tokens are encrypted at rest and stripped from account export payloads.
Accountant workspace access and support impersonation are separated, super-admin gated, and surfaced to the UI. Full CPA write-protection proof remains approval-gated before broad launch.
Administrative, support, and accounting events are recorded for review, with CPA boundary hardening tracked as a launch gate.
The production database has a documented restore drill with row-count verification in the project runbook.
Readiness checks fail closed for placeholder secrets, missing providers, stale migrations, failed jobs, and unhealthy services.
ficary is not claiming external certifications yet. Security posture is based on code-level controls, production readiness gates, database restore evidence, and active hardening. Enterprise certifications, formal penetration testing, and third-party attestations should be treated as roadmap items until completed.
Ready when your books are
Create a ficary account, connect the first source of truth, and build toward a cleaner close from day one.