Security
How we protect the data you connect
Sureshake reads your accounting system and holds financial detail about your company. This page describes how that data is handled, who can reach it, and what we do when something goes wrong. It is written to be read by your IT reviewer, not around them.
- Encryption
- In transit & at rest
- TLS 1.3 · AES-256
- Access
- Least privilege
- Role-scoped, logged, reviewed
- Ledger access
- Read-only
- Scoped tokens, revocable by you
- Disclosure
- security@sureshake.com
- Acknowledged within one business day
Data we hold
Sureshake stores the financial data required to produce and verify the reports you publish: the periods you pull from your accounting system, the statements and schedules you upload, the packages you publish, and the record of who they were shared with. We do not sell data, and we do not use one workspace's financial detail to serve another.
- Ledger connections
- Read-only, scoped to the periods you select, revocable by you at any time from the workspace.
- Published packages
- Retained so recipients can verify them. Unsharing revokes access; deletion is a separate, explicit request.
- Drafts
- Private to your workspace until you accept them. Never visible to recipients or to other workspaces.
Access control
Access inside a workspace is role-scoped: publishing a durable package requires an explicit entitlement, and stewards grant it per person. Every entitlement change is written to an audit log the workspace owner can read.
Internally, engineer access to production data is least-privilege, time-bounded, and logged. Support access to a customer workspace requires a request and leaves a record visible to that customer.
Infrastructure
- Encryption
- TLS 1.3 in transit; AES-256 at rest, including backups.
- Isolation
- Workspace data is logically separated and access-checked on every request path.
- Backups
- Encrypted, tested by restore on a recurring schedule.
- Dependencies
- Continuously scanned; security patches tracked to an SLA by severity.
Reporting a vulnerability
Send anything you find to security@sureshake.com. We acknowledge within one business day, keep you informed while we work, and credit reporters who want it. We will not pursue legal action against good-faith research that respects customer data and avoids service degradation.
Placeholder
Ask us the hard questions.
Named security questions get named answers from the person responsible for that control.