Security at BooksEZ.
A transparent account of how BooksEZ protects your platform's and your customers' financial data, spanning compliance, infrastructure, vulnerability response, and sub-processors. All current, all here.
The certifications standing behind every transaction.
Always on, always strong.
In transit, BooksEZ uses TLS 1.3 with HSTS preload and certificate pinning on partner endpoints. At rest, data is protected with AES-256-GCM and envelope encryption for sensitive fields. Keys are managed in AWS KMS with multi-region replication, automatic rotation, and HSM-backed master keys.
Highly sensitive fields, including bank account numbers, tax IDs, and signed agreements, receive an additional layer of field-level encryption with separate access logging.
Built on the unexciting fundamentals of fintech.
Multi-region, multi-AZ
Production runs across us-east-1 and us-west-2 with active-active failover. All services auto-scale with no single-AZ dependencies. Daily encrypted backups are retained for 35 days.
Zero-trust internal network
Production lives within a private VPC. Internal service-to-service traffic is mTLS-authenticated using SPIFFE identities, with no long-lived bastion hosts.
Least-privilege access
Single sign-on with hardware-key MFA across all production systems. Standing access to platform or end-customer data is rare and requires written justification.
24×7 security operations centre
Centralised logging with anomaly detection across the application, infrastructure, and identity layers. The security operations centre monitors round the clock.
SDLC with mandatory review
Mandatory code review on every change. Static analysis, dependency scanning, and secrets detection run in CI. Third-party penetration tests are conducted quarterly.
Single-tenant deployment available
Enterprise platforms can request a dedicated single-tenant deployment within their own AWS region, carrying the same security posture on dedicated infrastructure.
Spotted a vulnerability? Tell us.
BooksEZ operates a coordinated disclosure program with a public bug-bounty channel. Researchers acting in good faith under our safe-harbour policy will face no legal action. Encrypted submissions are strongly preferred.
The vendors that help us deliver the service.
A small set of sub-processors delivers parts of the service. Each is bound to security and confidentiality commitments equivalent to ours. BooksEZ notifies platform partners at least 30 days before adding any new sub-processor that handles data.
| Sub-processor | Purpose | Region |
|---|---|---|
| Amazon Web Services | Cloud infrastructure, KMS | US, EU, IN |
| Plaid | Bank-data connectivity | US |
| Stripe | Payment processing | US, EU |
| Datadog | Observability, application logging | US |
| Snowflake | Internal analytics warehouse (no PII) | US |
| Postmark | Transactional email delivery | US |
| Twilio | SMS notifications | US |
| Persona | Identity verification | US |
Sending a vendor security questionnaire?
Send it over. We tend to return them faster than your legal team can read them.
security@booksez.com