Security, access, and your data

How access is controlled, what the audit trail proves, the practices that matter most on your side, and what happens to your data if you leave.

ReferenceFor Business owners, Firm staff, Portal clients

How access is controlled

  • Sign-in is handled by an identity provider rather than by a password Books stores.
  • Access is granted per organization and, within it, per legal entity.
  • Roles determine what a person can do; entity scope determines what they can see.
  • API keys carry their own scoped access and can be revoked independently.
  • Every action is recorded in the audit trail with an actor and a timestamp.

What matters most on your side

Most real incidents in small businesses are not sophisticated. They are an ex-employee whose access was never removed, a payment redirected by a convincing email, or a document sent to the wrong address.

  1. Remove access the day someone leaves, and rotate any API key they created.
  2. Verify vendor payment detail changes by phone, on a number you already had.
  3. Turn on multi-factor authentication for everyone, without exception for seniority.
  4. Do not send financial documents by ordinary email.
  5. Review who has access quarterly — the list grows in ways nobody intends.
  6. Reconcile promptly. Unauthorized activity is caught by someone comparing to the statement.

Your data if you leave

  • Financial statements and the trial balance export as PDF and CSV.
  • The general ledger exports in full, which is what a successor system needs.
  • Lists — chart of accounts, customers, vendors, items — export as CSV.
  • Documents can be downloaded from storage.
  • The audit trail can be exported as an evidence bundle.

Common questions

Can Backline staff see my books?

Access by support staff is limited and logged. If you have a specific concern — a sensitive matter, a regulated context — raise it and ask what applies to your account rather than assuming either way.

What if I think there has been unauthorized access?

Remove the suspected access immediately, rotate API keys, review the audit trail for the period concerned, and contact support. Do not wait for certainty — reversing a precaution is cheap.

See alsoThe audit trail and chain verification

Where are the formal policies?

The public site carries the privacy policy, security page, subprocessor list, acceptable use policy, AI disclosures, and data controls.

Was this useful?

Read next

All administration