Built to be audited.
The books we run are evidence. Here is how we protect them.
Encryption, by default.
AES-256 at rest · TLS 1.3 in transit. Every business's books live in an isolated scope — nothing crosses tenant boundaries.
At rest
Data is encrypted at rest across every storage layer the ledger writes to.
In transit
Every connection — browser, API, or MCP client — is encrypted in transit before it reaches the ledger.
Business-scoped isolation
Every business's books live in their own scope. A user, a firm connection, or an agent only ever sees the businesses they have permission for.
SOC 2 Type II, underway.
SOC 2 Type II in progress, target Q1 2027.
Already in place
Encryption at rest and in transit, per-business permission isolation, and a tamper-evident audit trail on every action are live in production today — they don't wait on a certification date.
In progress
SOC 2 Type II in progress, target Q1 2027. We'll update this page — and every other surface that cites it — the day the report lands.
Agents move fast. The ledger stays defensible.
Every write an AI agent makes goes through the same rails: preview it, approve it, and know exactly who did it — human or agent.
A sample of the tools that pause for approval before they commit:
Dry-run before every write
Every write tool accepts dry_run and returns a preview of exactly what would change — nothing commits until the agent, or you, says so.
Approval gates on the risky ones
Sending, voiding, finalizing, and payment-linking tools pause for an explicit in-chat approval via MCP elicitation before they touch the ledger.
A tamper-evident audit trail
Every action lands in the same audit trail as human ones, tagged with the actor and a before/after — queryable by the audit tools themselves.
Scoped OAuth 2.1 access
Agent connections authenticate over OAuth 2.1, scoped to exactly what they're allowed to reach — no long-lived tokens to leak.
Every action, attributable.
Nothing happens in the books anonymously — not for a person, and not for an agent.
Actor + before/after on everything
Every read and write is tied to who did it, with a before/after captured on every change — the same trail whether the actor is a teammate or an AI agent.
Firm-level permission isolation
Firms managing many client businesses get scoped access per business — a connection only ever sees the businesses its user can access.
Found something? Tell us.
We run a responsible disclosure program with defined response timelines and reward tiers for security researchers who report vulnerabilities in good faith.
Security reviews, answered directly.
Send vendor security questionnaires and review requests to hello@ondayzero.com.