Security

Bookkeeping software has to protect the ledger and explain who touched it.

ficary is built around scoped access, encrypted financial tokens, audit evidence, and operational checks that make launch blockers visible before they become customer problems.

Session and account controls

ficary uses signed server-side session cookies, guarded app routes, and password confirmation for destructive account deletion.

Encrypted provider tokens

Sensitive provider tokens are encrypted at rest and stripped from account export payloads.

CPA and support visibility

Accountant access is read-only, support impersonation is super-admin gated, and active context is surfaced to the UI.

Audit trail

Administrative changes, impersonation events, CPA view changes, and blocked read-only writes are recorded for review.

Backup evidence

The production database has a documented restore drill with row-count verification in the project runbook.

Launch gates

Readiness checks fail closed for placeholder secrets, missing providers, stale migrations, failed jobs, and unhealthy services.

Current security posture

ficary is not claiming external certifications yet. Security posture is based on code-level controls, production readiness gates, database restore evidence, and active hardening. Enterprise certifications, formal penetration testing, and third-party attestations should be treated as roadmap items until completed.

Ready when your books are

Give accountants access without handing over your whole account.

Create a ficary account, connect the first source of truth, and build toward a cleaner close from day one.