Security & trust

Built to be audited.

The books we run are evidence. Here is how we protect them.

01 — Encryption & data handling

Encryption, by default.

AES-256 at rest · TLS 1.3 in transit. Every business's books live in an isolated scope — nothing crosses tenant boundaries.

At rest

Data is encrypted at rest across every storage layer the ledger writes to.

In transit

Every connection — browser, API, or MCP client — is encrypted in transit before it reaches the ledger.

Business-scoped isolation

Every business's books live in their own scope. A user, a firm connection, or an agent only ever sees the businesses they have permission for.

02 — Compliance roadmap

SOC 2 Type II, underway.

SOC 2 Type II in progress, target Q1 2027.

Already in place

Encryption at rest and in transit, per-business permission isolation, and a tamper-evident audit trail on every action are live in production today — they don't wait on a certification date.

In progress

SOC 2 Type II in progress, target Q1 2027. We'll update this page — and every other surface that cites it — the day the report lands.

03 — The agent safety model

Agents move fast. The ledger stays defensible.

Every write an AI agent makes goes through the same rails: preview it, approve it, and know exactly who did it — human or agent.

A sample of the tools that pause for approval before they commit:

send_invoicevoid_invoicefinalize_invoicemark_invoice_paidlink_bill_paymentcancel_bill

Dry-run before every write

Every write tool accepts dry_run and returns a preview of exactly what would change — nothing commits until the agent, or you, says so.

Approval gates on the risky ones

Sending, voiding, finalizing, and payment-linking tools pause for an explicit in-chat approval via MCP elicitation before they touch the ledger.

A tamper-evident audit trail

Every action lands in the same audit trail as human ones, tagged with the actor and a before/after — queryable by the audit tools themselves.

Scoped OAuth 2.1 access

Agent connections authenticate over OAuth 2.1, scoped to exactly what they're allowed to reach — no long-lived tokens to leak.

04 — Access & accountability

Every action, attributable.

Nothing happens in the books anonymously — not for a person, and not for an agent.

Actor + before/after on everything

Every read and write is tied to who did it, with a before/after captured on every change — the same trail whether the actor is a teammate or an AI agent.

Firm-level permission isolation

Firms managing many client businesses get scoped access per business — a connection only ever sees the businesses its user can access.

05 — Responsible disclosure

Found something? Tell us.

We run a responsible disclosure program with defined response timelines and reward tiers for security researchers who report vulnerabilities in good faith.

06 — Questions

Security reviews, answered directly.

Send vendor security questionnaires and review requests to hello@ondayzero.com.

Schedule a pilot