Financial information deserves serious protection

CFOly is designed to help accounting firms and business owners work with sensitive financial information.

We recognize the responsibility that comes with that access and are committed to clear, responsible security and privacy practices.

Performance line graph showing an overall performance score of 85% with a highlighted point indicating a 10% increase.

Required Security Sections

The security and development teams must provide verified language for each section.
Do not guess.
Data encryption
Confirm:
Encryption in transit
Encryption at rest
Supported protocols
Database encryption
Backup encryption
Key management

QuickBooks authorization

Confirm:

Whether OAuth is used
Information CFOly accesses
Whether access is read-only
Information CFOly stores
Refresh frequency
Retention period
How access is revoked
What happens after disconnection
Bar chart with multiple vertical bars in peach and blue colors representing values compared to a dotted red goal line.
Hosting

Confirm:

Hosting provider
Hosting region
Backup schedule
Disaster-recovery process
Availability monitoring
Logging
Infrastructure access
Account security

Confirm:

Password requirements
Multi-factor authentication
Session duration
Account lockout
User permissions
Firm and client separation
Administrative access
AI and customer information

Explain:

Which AI providers process customer information
Whether customer information is used to train general models
Provider retention periods
How prompts and responses are handled
Whether humans may access customer content
Whether personally identifiable information is filtered
Whether users may delete information
Performance line graph showing an overall performance score of 85% with a highlighted point indicating a 10% increase.

Incident response

Confirm:

Security contact
Incident-response process
Customer-notification process
Breach-response procedures

Compliance

List only certifications or compliance programs that have actually been completed.

Do not publish:

SOC 2
ISO 27001
HIPAA
PCI compliance
GDPR compliance
Bank-level security

unless the claim has been reviewed and substantiated.

Bar chart with multiple vertical bars in peach and blue colors representing values compared to a dotted red goal line.