Security

Bookkeeping software has to protect the ledger and explain who touched it.

ficary is built around scoped access, encrypted financial tokens, audit evidence, and operational checks that make launch blockers visible before they become customer problems.

Session and account controls

ficary uses signed server-side session cookies, guarded app routes, and password confirmation for destructive account deletion.

Encrypted provider tokens

Sensitive provider tokens are encrypted at rest and stripped from account export payloads.

CPA and support visibility

Accountant workspace access and support impersonation are separated, super-admin gated, and surfaced to the UI. Full CPA write-protection proof remains approval-gated before broad launch.

Audit trail

Administrative, support, and accounting events are recorded for review, with CPA boundary hardening tracked as a launch gate.

Backup evidence

The production database has a documented restore drill with row-count verification in the project runbook.

Launch gates

Readiness checks fail closed for placeholder secrets, missing providers, stale migrations, failed jobs, and unhealthy services.

Current security posture

ficary is not claiming external certifications yet. Security posture is based on code-level controls, production readiness gates, database restore evidence, and active hardening. Enterprise certifications, formal penetration testing, and third-party attestations should be treated as roadmap items until completed.

Ready when your books are

Give accountants a clearer workspace without handing over your whole account.

Create a ficary account, connect the first source of truth, and build toward a cleaner close from day one.