Skip to main content
Trust & Security

How AccountDesq protects your data

AccountDesq is an early-stage product. What follows describes what's actually built and running today - not aspirational claims or certifications we don't hold.

Workspace-level data isolation

Every workspace's data is scoped and isolated at the database level - one tenant's records are never queryable from another workspace's context, enforced by the database itself, not just application logic.

Role-based access control

Fixed system roles (Owner, Admin, Finance Manager, Accountant, Sales Manager, Viewer) or a custom role cloned from one, with permissions grouped by module. Access can also be scoped to specific branches or warehouses, so a team member only sees the locations they actually work at.

Maker-checker approvals

Spending limits are configurable per team member. Transactions above a set threshold require a second, different person's approval before they take effect - the same control described in our guide to financial controls for growing teams.

Audit trail

Financial records - journal entries, customer and vendor changes, and more - carry a real audit history: who did what, and when. Support access to a member's view ("view as") is time-boxed to 30 minutes, fully logged, and can never target an Owner account.

Encryption

All traffic is encrypted in transit (HTTPS, enforced at the edge). Particularly sensitive fields, such as vendor payment/remittance details, are encrypted at rest.

Your data, your control

You can request export or anonymization of your account data, and configure data retention preferences - real, working capabilities, not just a policy statement.

Found a security issue?

If you believe you've found a security vulnerability, please email us directly rather than filing a public issue - we'll respond and work with you on it.

sales@accountdesq.com

This page describes technical practices, not a legal or compliance certification. See our Privacy Policy for how we handle your data.