Company-scoped access
Core financial records are scoped to a company. Database row-level security policies check active company access before allowing authenticated users to work with company data.
Security
switchbooks uses company-level access controls and established infrastructure providers to protect the bookkeeping data entrusted to the platform.
Last reviewed July 23, 2026.
Core financial records are scoped to a company. Database row-level security policies check active company access before allowing authenticated users to work with company data.
switchbooks uses Supabase Auth for account sessions, including emailed one-time-code flows. Company owners can invite team members and manage who has access to each company.
Bank connections are established with Plaid Link. Plaid access tokens are stored as secrets in Supabase Vault rather than in the application’s plaintext Plaid item records.
Subscription checkout and billing management use Stripe Checkout and the Stripe Customer Portal. Incoming Stripe events are checked with webhook signatures before switchbooks processes them.
This page describes controls that are implemented in the current product. It is not a claim that switchbooks holds a SOC 2, ISO 27001, or similar certification. We will list independent certifications here if that changes.
If you believe you found a security issue, email info@switchbooks.ai with a clear description and steps to reproduce it. Please do not include live bank credentials, access tokens, or unnecessary customer data.
Review how switchbooks handles personal information in the Privacy Policy, and read the rules governing use of the service in the Terms.