Security

How we protect the data you connect

Sureshake reads your accounting system and holds financial detail about your company. This page describes how that data is handled, who can reach it, and what we do when something goes wrong. It is written to be read by your IT reviewer, not around them.

Encryption
In transit & at rest
TLS 1.3 · AES-256
Access
Least privilege
Role-scoped, logged, reviewed
Ledger access
Read-only
Scoped tokens, revocable by you
Disclosure
security@sureshake.com
Acknowledged within one business day

Data we hold

Sureshake stores the financial data required to produce and verify the reports you publish: the periods you pull from your accounting system, the statements and schedules you upload, the packages you publish, and the record of who they were shared with. We do not sell data, and we do not use one workspace's financial detail to serve another.

Ledger connections
Read-only, scoped to the periods you select, revocable by you at any time from the workspace.
Published packages
Retained so recipients can verify them. Unsharing revokes access; deletion is a separate, explicit request.
Drafts
Private to your workspace until you accept them. Never visible to recipients or to other workspaces.

Access control

Access inside a workspace is role-scoped: publishing a durable package requires an explicit entitlement, and stewards grant it per person. Every entitlement change is written to an audit log the workspace owner can read.

Internally, engineer access to production data is least-privilege, time-bounded, and logged. Support access to a customer workspace requires a request and leaves a record visible to that customer.

Infrastructure

Encryption
TLS 1.3 in transit; AES-256 at rest, including backups.
Isolation
Workspace data is logically separated and access-checked on every request path.
Backups
Encrypted, tested by restore on a recurring schedule.
Dependencies
Continuously scanned; security patches tracked to an SLA by severity.

Reporting a vulnerability

Send anything you find to security@sureshake.com. We acknowledge within one business day, keep you informed while we work, and credit reporters who want it. We will not pursue legal action against good-faith research that respects customer data and avoids service degradation.

Placeholder

Certification claims (SOC 2, ISO 27001, penetration-test cadence) are deliberately absent until they are true. They will be added here once the audit completes.

Ask us the hard questions.

Named security questions get named answers from the person responsible for that control.