Security

Financial data deserves clear, practical safeguards.

switchbooks uses company-level access controls and established infrastructure providers to protect the bookkeeping data entrusted to the platform.

Last reviewed July 23, 2026.

Company-scoped access

Core financial records are scoped to a company. Database row-level security policies check active company access before allowing authenticated users to work with company data.

Authentication and team controls

switchbooks uses Supabase Auth for account sessions, including emailed one-time-code flows. Company owners can invite team members and manage who has access to each company.

Protected bank connection tokens

Bank connections are established with Plaid Link. Plaid access tokens are stored as secrets in Supabase Vault rather than in the application’s plaintext Plaid item records.

Stripe-hosted billing

Subscription checkout and billing management use Stripe Checkout and the Stripe Customer Portal. Incoming Stripe events are checked with webhook signatures before switchbooks processes them.

What we do not claim

This page describes controls that are implemented in the current product. It is not a claim that switchbooks holds a SOC 2, ISO 27001, or similar certification. We will list independent certifications here if that changes.

Report a security concern

If you believe you found a security issue, email info@switchbooks.ai with a clear description and steps to reproduce it. Please do not include live bank credentials, access tokens, or unnecessary customer data.

Privacy and legal information

Review how switchbooks handles personal information in the Privacy Policy, and read the rules governing use of the service in the Terms.