Security & data handling
Your financial data stays yours, and nothing moves without a name on it.
Accruna holds access to a company's most sensitive operational data. That deserves specifics rather than reassurance, so this page sets out the access model, the approval controls, the audit trail, and — just as importantly — what we are not currently claiming.
The short version
- Least-privilege access for people and agents alike
- Human approval required for payments, journals and policy overrides
- Immutable audit trail with before-and-after values
- Encryption in transit and at rest
- No sale, sharing or model training on your data
- Full export and credential revocation on exit
Control framework
Five controls the engagement depends on.
These are operational commitments, not aspirational statements. Each one has an owner and a way to verify it.
Encryption everywhere
Connections use TLS. Ledger data, documents and stored credentials are encrypted at rest. API tokens are held encrypted and are excluded from application logs.
Role-based, least-privilege access
Access is scoped by role, entity and function. Agents hold the narrowest permissions their task requires — a coding agent cannot initiate a payment.
Immutable audit trail
Every action records the actor, timestamp, affected record and the values before and after. Entries are reversed, never deleted, so history stays intact.
Human approval controls
Payments, journal postings and policy overrides require a named human approval within an authority limit you set. Agents cannot approve their own proposals.
Separation of duties
Preparing, approving and posting are separated. Supplier bank detail changes require dual authorisation; period reopening follows a documented process.
Observable operations
Sync health, rejected rows, exception ageing and approval history are visible to you at all times. You should not have to ask whether something ran.
Access model
Who can see and do what.
Access is granted by role and reviewed on a schedule. Standing broad access is not granted to anyone, including our own staff.
| Role | Ledger access | Can approve | Can move money |
|---|---|---|---|
| Accruna agents | Scoped to a single function, read plus narrowly defined writes | No | No |
| Engagement accountant | Full read, write on assigned entities | Within their authority limit | No |
| Accounting manager | Full read, write on assigned portfolio | Yes, within portfolio limits | No |
| Client controller | Full read and write on their entities | Yes, per your matrix | Via your bank authorisation |
| Client admin | Full read; configuration rights | Yes | Via your bank authorisation |
| Department head | Read scoped to their cost centre | Within their budget authority | No |
| External auditor | Read-only, time-boxed, revoked on request | No | No |
How access is granted
By role, with a named approver, and with an expiry for temporary grants. Delegation carries a date range rather than being indefinite.
How it is reviewed
A permission matrix is reviewed with you periodically, and an exportable version is available at any time. Departures trigger immediate revocation.
How it is verified
Every access event is logged. You can request a report of who accessed what and when, for any period, including our own staff.
Agent security
Autonomy needs boundaries, not trust.
Agents are treated as non-human identities with explicit authority limits. They are not given broad credentials and asked to behave — their permissions are scoped so that a mistake cannot become a large one.
- EntryJE-2025-09-0442
- Proposed byLedger agent v4.2
- BasisRule R-0142 + 14 precedents
- Approved byM. Okonjo, CPA
- Approved at28 Sep 2025, 13:22
- Value$14,820.00
- ReversibleYes — reversal preserves original
Why this matters in practice
Most automation risk is not a model being wrong. It is automation having more authority than the situation warranted, and no record of what it did. Both are design decisions, and both are avoidable.
Data lifecycle
What happens to your data at each stage.
From the first connection to the day the engagement ends — stated in advance rather than negotiated at exit.
Collection
Only the data required for the engagement. Connections you authorise, scoped as narrowly as workable.
Processing
Encrypted at rest, access logged, and excluded from any third-party model training.
Retention
Held for the engagement and the agreed retention window that follows, driven by record-keeping obligations.
Return and deletion
Full export on request, credentials revoked, then deletion with written confirmation.
Sub-processors
Third parties in the chain
Running this needs hosting, storage and connection infrastructure. We will give you the current list of sub-processors on request, tell you before a new one is added where it affects your data, and we do not permit sub-processors to use your data for their own purposes.
- Named list available on request, with purpose and location
- Advance notice of changes affecting your data
- Contractual restrictions on use, retention and onward transfer
Your rights
Control you keep at all times
- Access report covering who viewed or changed your data
- Export of ledger history, workpapers and audit logs
- Revocation of any connection, effective immediately
- Deletion request subject to record-keeping obligations
- Written confirmation when revocation and deletion complete
What we do not claim
Being specific about the limits.
Compliance claims are easy to make and expensive to verify. These are the things we are deliberately not asserting, so you can assess the engagement without having to discount for marketing.
- Certifications
- We do not currently hold or claim a SOC 2 report, ISO 27001 certification or equivalent. Our controls are designed with those frameworks in mind, and we will say plainly when that changes rather than implying it now.
- Regulatory status
- Accruna is not a licensed audit firm and does not issue audit opinions. We prepare and maintain the workpapers an auditor will request; the opinion comes from your auditor.
- Filing
- Statutory tax filing is not part of the core engagement. We maintain the ledger and schedules that filing depends on, and can scope filing separately with the appropriate licensed preparer.
- Guarantees
- We do not publish accuracy percentages or close-time guarantees. What we commit to is a documented process, named accountability and service levels we are willing to be measured against.
- Data residency
- Default hosting region is stated during scoping. Specific residency requirements can usually be accommodated, but we will confirm rather than assume.
Operational practice
How the firm operates day to day.
Security is mostly operational discipline. These are the practices behind the controls above.
Identity and access
- Multi-factor authentication required for all staff accounts
- Access granted by role request with a named approver
- Immediate revocation on departure or role change
- No shared accounts; every action is attributable to a person
Change and review
- Rule and threshold changes versioned with an effective date
- Period locks applied at close and reopening documented
- Peer review on journal entries above a materiality threshold
- Quarterly review of access, thresholds and exceptions together
Continuity
- Backups taken and restoration tested, not merely configured
- Documented process for a period in which systems are unavailable
- Named escalation contacts on both sides of the engagement
- Exportable data so continuity does not depend on us
Encrypted
In transit and at rest
Ledger data, documents and credentials.
Logged
Every action
Actor, timestamp and before/after values.
Approved
By a named human
No agent approves its own proposal.
Security questions
Questions we are asked in reviews.
Send us your security questionnaire and we will complete it honestly, including the parts we cannot yet satisfy.
The accountants and managers assigned to your engagement, and the agents performing scoped tasks within it. Access is role-based, so a team member working on another client cannot see your data, and no one has standing access to all engagements.
You can request an access report for any period showing who viewed or changed what, including our staff. Where a client prefers tighter scoping — for example restricting payroll visibility to one named manager — that is a configuration we set at onboarding.
No. Agents prepare payment batches and match supporting documentation, but releasing funds requires a human authorisation using your own banking credentials and controls. Accruna never holds the authority to move money unilaterally.
This is a deliberate design boundary rather than a current limitation. Even if a future capability allowed it, the authority limit would remain a configuration you control.
No. Your ledger data is not used to train third-party models, and it is not used to train models for other clients.
What does happen is that coding decisions you approve become precedents within your own ledger — so the agent's suggestions for your accounts improve over time. That precedent set is client-specific and never shared.
It is identified, reversed and corrected with the original preserved. Because every entry carries its source, its basis and its approval, tracing the cause is a lookup rather than an investigation.
If a pattern of errors emerges, we will tell you and adjust the thresholds or rules that produced it. We would rather narrow an agent's authority than defend its output.
On cloud infrastructure, in the default region stated during scoping. Specific residency requirements are best raised early — they are usually accommodating, but they change architecture and should not be a surprise midway through contracting.
Sub-processors involved in hosting, storage and connectivity are listed on request, and you will be told before a change that affects your data.
You can request documentation of our controls and an access report, and we will complete security questionnaires in full. On-site or remote control audits are available on larger engagements and are agreed in the engagement letter.
If a control you require does not exist yet, we will tell you that directly. Discovering a gap during evaluation is considerably cheaper than discovering it during an external audit.
Your ledger, documents and history remain in your systems throughout, because Accruna operates on your data rather than holding a separate copy of the business's books. Connections are revoked promptly after the final period is signed off.
Any working data we hold is exported to you on request and deleted according to the agreed retention window, with written confirmation when both are complete.
Send us your security requirements.
If your organisation needs a questionnaire completed, a specific control documented, or a residency commitment confirmed, we would rather work through it before you shortlist us.