Security & trust

You are handing us the whole ledger.

That deserves more than a badge on a footer. Here is precisely what we can see, what we can do, and what we have deliberately made ourselves unable to do.

Read-only by default

Bank and card connections are read-only. We can see your transactions; we cannot move your money. There is no flow in our system that initiates a payment.

Credentials we never hold

Feeds are connected through regulated aggregators using tokenised consent. We do not store your online banking username or password, because we never receive them.

Encrypted end to end

TLS 1.2+ in transit, AES-256 at rest, with keys managed separately from the data they protect. Documents and receipts are stored in private object storage, never a public bucket.

Least privilege, logged

Staff access is role-scoped and time-boxed, granted per engagement rather than per employee. Every access to a client ledger is logged and reviewable.

A complete audit trail

Every posting records its source, its evidence, its confidence and whether a human or an agent made it. Corrections are journalled — nothing is silently rewritten.

Your data is not training data

We do not train shared models on the contents of your ledger, and your data is never used to serve another client. Model providers operate under zero-retention terms.

The questions
a CFO asks.

Need our full security documentation, a DPA or a subprocessor list? Email security@acruee.com.

In the region you operate in — US clients in the United States, UK and EU clients in the European Economic Area. Data does not cross regions for processing, and we will tell you exactly which subprocessors touch it.

Still reading

Ask us the hard question.

Whatever it is about how we hold your data, ask it before you sign rather than after. We would rather lose a deal than be vague.