Trust

Security at Backline

Backline uses layered safeguards designed to protect the financial and operational information entrusted to Backline Books. Security is a shared responsibility and no system eliminates every risk.

Effective August 7, 2026Version 2026.08.07

1. Security program

Backline maintains administrative, technical, and organizational measures proportionate to the Service and information involved. Controls evolve with the product, threat environment, and provider capabilities. This page is a current overview, not a certification, warranty, service-level agreement, or promise that an incident cannot occur.

2. Data protection

  • HTTPS/TLS protects supported network traffic in transit.
  • Managed infrastructure providers protect stored application and database data with encryption at rest.
  • Active QuickBooks, Plaid, and TaxJar integration credentials use dedicated, versioned authenticated encryption at the application layer; historical compatibility data is restricted to migration paths.
  • Secrets are kept outside source code in managed environment configuration, and public-browser code is not intended to receive server credentials.
  • Backups and provider recovery features support continuity, subject to tested procedures and applicable service terms.

3. Identity and access

  • Managed authentication, authenticated sessions, and organization-aware application authorization restrict access.
  • Roles and permissions are designed to limit users and personnel to authorized functions and customer workspaces.
  • OAuth state and callbacks are validated, and supported financial connections use provider authorization flows rather than collecting provider passwords.
  • Customer administrators control invitations, membership, roles, connected services, and many recipient or approval decisions.

Tenant isolation is currently enforced primarily at the application layer. Customers with mandatory database row-level security or other prescriptive requirements should confirm them in a signed agreement before use.

4. Application and infrastructure safeguards

  • Central browser-security headers include content-security, transport-security, anti-framing, MIME-sniffing, referrer, and permissions policies.
  • Code review, automated type and lint checks, unit and integration tests, secret scanning, API-route inventory, and security-control checks support change management.
  • Application logging, error monitoring, security events, dependency review, and uptime signals support investigation and response.
  • Public webhooks and machine-to-machine routes use provider signatures, scoped credentials, or other route-appropriate authentication where implemented.
  • Human review and authorization controls are designed to bound automated accounting actions and prevent an agent from approving its own work.

5. Connected financial platforms

QuickBooks connections use OAuth 2.0 and the QuickBooks Online Accounting scope; Backline does not request an Intuit password or the QuickBooks Payments scope. Bank connections use an approved financial-data provider, and Backline does not receive online-banking passwords. Customers can revoke supported connections through the provider or request disconnection and deletion from Backline.

6. Personnel and service providers

Access is granted based on business need and restricted through provider and application controls. Service providers support hosting, data, identity, monitoring, communications, workflow, financial connectivity, and optional automated features. Providers are expected to process information for contracted purposes and applicable obligations. See Subprocessors & Service Providers.

7. Secure development and known limitations

Backline tracks production-readiness findings and remediates them according to severity. A successful test or control reduces risk but does not prove the absence of vulnerabilities. Before broad or regulated deployment, customers should complete their own risk assessment and contract for any required certifications, penetration tests, recovery objectives, data residency, regulated-data handling, or industry-specific controls. Backline does not claim SOC 2, ISO 27001, PCI DSS, HIPAA, or other certification on this page.

8. Customer responsibilities

  • Use unique accounts and secure authentication methods; never share sessions or verification codes.
  • Grant minimum necessary access, review membership regularly, and promptly remove departed or reassigned users.
  • Keep devices, browsers, email accounts, and connected platforms secure and current.
  • Verify account details, approvals, report recipients, exports, and automated suggestions before acting.
  • Do not place passwords, private keys, bank credentials, payment-card security codes, or prohibited regulated data into free-text fields or support email.
  • Promptly report suspected compromise, misdirected data, or unusual activity.

9. Incident response

Backline investigates suspected incidents, works to contain and remediate confirmed issues, preserves relevant records, and notifies affected customers or authorities when required by law or contract. Notification timing and content depend on the facts, investigation, provider coordination, and legal requirements.

10. Responsible disclosure

If you believe you found a vulnerability, avoid accessing, changing, downloading, or retaining data that is not yours; do not disrupt availability, use social engineering, or test against third-party systems. Email admin@backlinebusinesssolutions.com with the affected URL, non-sensitive reproduction steps, and potential impact. Do not include credentials or live financial data. We will acknowledge good-faith reports and coordinate appropriate validation and remediation. Testing authorization must be obtained in writing in advance.

11. Security documentation

Customers may request a security questionnaire, available architecture information, or contractual security terms. Disclosure may require confidentiality protections and may be limited to protect customers and systems.

Questions? Contact admin@backlinebusinesssolutions.com. Do not send credentials or sensitive financial records by ordinary email.