← Back to AI Accountant

Security & Resilience

Last reviewed: October 5, 2026

Access control

Email verification is required. Organization data is isolated with database row-level security, and sensitive actions check both membership and role. Anonymous sign-in is disabled.

Data protection

Private credentials are kept out of the browser and source repository. Receipt files use private storage. Connections to the application and service providers use encrypted HTTPS transport.

Auditability

Administrative and accounting events are recorded to support review. Posted accounting entries use balanced double-entry records, and closed periods are protected against ordinary edits.

Backups and recovery

The production database uses the backup facilities included with its Supabase plan. Before serving paying customers, NaNach Systems will retain scheduled off-platform exports, document recovery ownership, and test restoration regularly. Users should retain original source documents independently.

Responsible reporting

If you believe you found a security problem, do not access other users’ data. Preserve the details and report the issue privately through the account channel used to provide service access.