Trust · Security

Security at BooksEZ.

A transparent account of how BooksEZ protects your platform's and your customers' financial data, spanning compliance, infrastructure, vulnerability response, and sub-processors. All current, all here.

Compliance & certifications

The certifications standing behind every transaction.

SOC 2
Type II
Annual audit covering security, availability, confidentiality, and processing integrity.
PCI DSS
Level 1
The highest tier of card-data security. We never store full card numbers ourselves.
ISO 27001
Certified
Information-security management system, externally audited annually.
GDPR · CCPA
Aligned
DPA, SCCs, UK addendum, and a single workflow covering US state-level laws.
Encryption

Always on, always strong.

In transit, BooksEZ uses TLS 1.3 with HSTS preload and certificate pinning on partner endpoints. At rest, data is protected with AES-256-GCM and envelope encryption for sensitive fields. Keys are managed in AWS KMS with multi-region replication, automatic rotation, and HSM-backed master keys.

Highly sensitive fields, including bank account numbers, tax IDs, and signed agreements, receive an additional layer of field-level encryption with separate access logging.

Encryption · live
algorithm   AES-256-GCM
kms   aws-kms · multi-region
rotation   90 days, automated
hsm   CloudHSM-backed root
field-level   tax_id, bank_acct
in-transit   TLS 1.3 / HSTS
Infrastructure

Built on the unexciting fundamentals of fintech.

01

Multi-region, multi-AZ

Production runs across us-east-1 and us-west-2 with active-active failover. All services auto-scale with no single-AZ dependencies. Daily encrypted backups are retained for 35 days.

02

Zero-trust internal network

Production lives within a private VPC. Internal service-to-service traffic is mTLS-authenticated using SPIFFE identities, with no long-lived bastion hosts.

03

Least-privilege access

Single sign-on with hardware-key MFA across all production systems. Standing access to platform or end-customer data is rare and requires written justification.

04

24×7 security operations centre

Centralised logging with anomaly detection across the application, infrastructure, and identity layers. The security operations centre monitors round the clock.

05

SDLC with mandatory review

Mandatory code review on every change. Static analysis, dependency scanning, and secrets detection run in CI. Third-party penetration tests are conducted quarterly.

06

Single-tenant deployment available

Enterprise platforms can request a dedicated single-tenant deployment within their own AWS region, carrying the same security posture on dedicated infrastructure.

Vulnerability disclosure

Spotted a vulnerability? Tell us.

BooksEZ operates a coordinated disclosure program with a public bug-bounty channel. Researchers acting in good faith under our safe-harbour policy will face no legal action. Encrypted submissions are strongly preferred.

Sub-processors

The vendors that help us deliver the service.

A small set of sub-processors delivers parts of the service. Each is bound to security and confidentiality commitments equivalent to ours. BooksEZ notifies platform partners at least 30 days before adding any new sub-processor that handles data.

Sub-processorPurposeRegion
Amazon Web ServicesCloud infrastructure, KMSUS, EU, IN
PlaidBank-data connectivityUS
StripePayment processingUS, EU
DatadogObservability, application loggingUS
SnowflakeInternal analytics warehouse (no PII)US
PostmarkTransactional email deliveryUS
TwilioSMS notificationsUS
PersonaIdentity verificationUS

Sending a vendor security questionnaire?

Send it over. We tend to return them faster than your legal team can read them.

security@booksez.com