Session and account controls
ficary uses signed server-side session cookies, guarded app routes, and password confirmation for destructive account deletion.
Security
ficary is built around scoped access, encrypted financial tokens, audit evidence, and operational checks that make launch blockers visible before they become customer problems.
ficary uses signed server-side session cookies, guarded app routes, and password confirmation for destructive account deletion.
Sensitive provider tokens are encrypted at rest and stripped from account export payloads.
Accountant access is read-only, support impersonation is super-admin gated, and active context is surfaced to the UI.
Administrative changes, impersonation events, CPA view changes, and blocked read-only writes are recorded for review.
The production database has a documented restore drill with row-count verification in the project runbook.
Readiness checks fail closed for placeholder secrets, missing providers, stale migrations, failed jobs, and unhealthy services.
ficary is not claiming external certifications yet. Security posture is based on code-level controls, production readiness gates, database restore evidence, and active hardening. Enterprise certifications, formal penetration testing, and third-party attestations should be treated as roadmap items until completed.
Ready when your books are
Create a ficary account, connect the first source of truth, and build toward a cleaner close from day one.