Trust

Security

You are about to let someone into your books. Here is exactly what that grants, what we hold, and how you take it back.

Last updated 27 August 2026

We never hold your passwords

There is no point in our process where you type a password for QuickBooks, Ramp, Clio or Gusto into anything of ours. Access is an invitation you issue from inside each system, under your own administrator account.

That matters for a reason beyond convenience: a credential you never shared cannot be leaked by us, and access you granted from your own console can be withdrawn from the same console without asking us first.

What the access actually permits

  • Connectinga source through Intuit’s standard sign-in lets us read your books, so your figures appear on your screens.
  • Inviting us as your accountant is what lets a correction be posted. Corrections are queued for a person to approve; nothing posts automatically to your ledger.

Two different grants, and the first does not imply the second. A firm that wants reporting only can stop at the connection.

Revoking it

Immediately, from your side, without notice or our involvement: remove the CountCore user in QuickBooks, Ramp, Clio or Gusto, or disconnect the source in CountCore under Settings, Connections. Disconnecting in CountCore revokes the token with the provider rather than only forgetting it locally.

Where your data sits

The application runs on Vercel and the database is Neon, both in the United States. Your accounting records remain in your own accounting system as the system of record — we read from it and write back approved corrections. We are not a place your books move to.

Traffic is served over TLS. Sign-in uses a password you choose, stored only as a scrypt hash, and a signed session cookie re-verified on each request. We do not use a third-party identity provider.

What we are still building

Two things a careful reader should know are not in place yet, said plainly rather than left for you to discover:

  • Connection tokens are not yet encrypted at rest.They sit in the database as issued by the provider, protected by the database’s own access controls rather than by a separate application key. Encrypting them is scheduled work, and this page will say so when it is done.
  • We have not completed a SOC 2 examination. When that changes we will publish the report rather than the badge.

Reporting something

If you believe you have found a vulnerability, tell us through contact and we will respond. We will not threaten anyone who reports a problem in good faith.