ConsulBooks
Menu
Start free preview

SECURITY, WITHOUT VAGUE SUPERLATIVES

The controls we operate—and the claims we do not make.

ConsulBooks handles sensitive financial records. We publish the concrete safeguards in the current product, distinguish provider responsibilities, and do not claim certifications or absolute security that we have not earned.

Required MFAAuthenticator code before financial access
Plaid-hosted sign-inNo bank password enters ConsulBooks
Encrypted tokensAES-256-GCM application encryption
Audit historyImportant bookkeeping actions remain traceable
01

Identity and MFA

Email and password authentication is handled by the configured identity provider. ConsulBooks then requires an authenticator-based second factor before the financial workspace or Plaid Link can open.

  • AAL2 session required for financial APIs
  • Individual user sessions
  • Sign-out clears the saved Plaid OAuth resume token
02

Institution connection

Plaid Link handles institution discovery, bank authentication, consent, and account selection. ConsulBooks receives a protected access token—not the customer's bank username or password.

  • Selected U.S. institutions
  • OAuth redirect bound to the originating workspace
  • Connection can be revoked from Business setup
03

Secrets and tokens

Plaid access tokens are encrypted before database storage with AES-256-GCM, a random 96-bit initialization vector, and a server-side 32-byte key. Secrets never ship to browser code.

  • Authenticated encryption
  • Versioned ciphertext format
  • Production configuration validation
04

Webhook verification

ConsulBooks checks the signed Plaid webhook JWT, timestamp, key identity, signature, and raw-body SHA-256 before accepting an event. Body size, key fetching, and connection requests are bounded.

  • ES256 verification
  • Replay-age check
  • Positive and negative verification-key caching
05

Workspace isolation

Bookkeeping reads and writes are resolved through the authenticated owner's business ID. Connected items, accounts, transactions, rules, journals, and audit events are scoped to that workspace.

  • Server-side ownership lookup
  • Business-scoped database statements
  • No cross-client vendor memory
06

Export and deletion

Customers can export records, disconnect an institution, or permanently delete a workspace. A disconnect revokes the future feed while retaining imported ledger history; full deletion attempts revocation before local removal.

  • Data portability
  • Exact-name deletion confirmation
  • Partial revocation failures remain visible and retryable

FINANCIAL DATA FLOW

Your bank credentials stay with the bank and Plaid.

  1. 1
    You approve access in Plaid Link

    The institution authentication and account-selection experience is provided by Plaid.

  2. 2
    ConsulBooks stores an encrypted connection token

    The server encrypts the token; the browser never receives the long-lived access token.

  3. 3
    Posted transactions enter your private workspace

    Pending items are skipped until posted. Updates are deduplicated and tied to the selected financial account.

  4. 4
    You review, export, disconnect, or delete

    Human decisions and important changes remain in the workspace audit history.

WHAT WE DO NOT CLAIM

Evidence before adjectives.

ConsulBooks does not currently claim SOC 2 certification, ISO 27001 certification, PCI certification, “unhackable,” “zero-knowledge,” “bank-grade,” or categorically stronger security than QuickBooks, Xero, or another provider.

Security is a continuing operating program, not a landing-page badge. The service may change as controls, independent review, incident processes, vendor management, and customer access mature.

To report a potential vulnerability or security concern, email security@consulbooks.com. Do not include bank credentials, passwords, access tokens, or unnecessary personal data.

RELEVANT DOCUMENTS

Privacy, terms, and connection provider details.