Trust & Security

How we handle your clients' data

When you connect a client's books to DataFloat, you're putting your professional reputation behind that decision. This page explains exactly what we do with their data, where it goes, and what we have not built yet.

What DataFloat does

  • Read from QuickBooks, one direction only
  • Give every client its own database schema
  • Encrypt in transit (TLS) and at rest (AES-256)
  • Require a verified email before any session

What it never does

  • Write anything back to your books
  • Store your QuickBooks credentials or tokens
  • Use your data to train AI models
  • Sell or share data with brokers or advertisers

What we have not built

  • SOC 2 certification
  • Self-serve deletion (email us and we do it)

Your accounting data

What our QuickBooks connection can and cannot do

DataFloat reads from QuickBooks. It does not write to it. No journal entry, invoice, account, or transaction in your client's books is ever created, edited, or deleted by DataFloat. Data moves in one direction only, out of QuickBooks and into your workspace.

We want to be precise about one thing, because you will see it on the Intuit consent screen. Intuit's accounting permission is a single combined scope that covers both reading and writing, and they do not offer a read-only version of it. So the consent screen will show broader permission than we actually use. We use it to read. Our sync runs through Fivetran, a managed data pipeline that only extracts data, and there is no code path in DataFloat that writes back to QuickBooks.

We also do not keep your QuickBooks credentials. DataFloat stores only the connection metadata it needs to identify your workspace: a connector ID, a schema name, and your QuickBooks company ID. Your access and refresh tokens are held by Fivetran and never land in our database.

We sync only what the product uses. Tables we have no use for are disabled at the connector before the first sync runs, so they are never pulled at all.

Multi-client work

How we keep your clients separated

If you run a book of clients, the risk you care about is not abstract. It is one client's numbers appearing in another client's report. We designed for that specifically.

Every client you connect syncs into its own dedicated schema inside our database, not into a shared table separated by a customer ID column. Each schema name is validated against a strict pattern before it is ever used, and every query runs inside a transaction whose search path is pinned to that single schema and reset automatically when the transaction ends.

Our AI agents run under a policy layer that is enforced in code, not by prompting. Any action flagged as crossing a client boundary is rejected before it executes. Actions that touch personal information are restricted to read-only. Actions that would modify financial data are refused unless they carry an audit record of the prior state.

Artificial intelligence

What the AI sees, and what it never does

DataFloat's AI features are built on Claude, from Anthropic. When you ask a question about your data, the relevant portion of that data is sent to Anthropic's API to produce the answer.

Your data is never used to train AI models. Anthropic does not train its models on data submitted through their commercial API. We do not train models on your data either, and we never will without asking you first in plain language.

We do not sell your data, and we do not share it with advertisers or data brokers. The companies listed in the subprocessors section below are the complete set of third parties that touch your clients' financial data, and each one is there because the product needs it to function.

Data residency

Where your data actually lives

Your data is processed in Canada and stored in the United States.

The pipeline that moves your data out of QuickBooks runs in Montreal, Canada. The database where that data comes to rest is hosted in Northern Virginia, in the United States. Because the stored copy sits on US infrastructure, it is subject to US legal process, and Canadian firms with public sector clients or Quebec operations should factor that into their own assessments.

All data is encrypted in transit using TLS, and encrypted at rest using AES-256.

Account security

Protecting the account itself

A financial data tool is only as secure as the login in front of it. We hold the account layer to the same standard as the data layer.

  • No session is issued until you have verified your email address. An unverified account cannot be used to reach any data.
  • Login, signup, and password-reset endpoints are rate limited to blunt credential-stuffing and brute-force attempts.
  • Completing a password reset revokes every existing session, so an attacker holding a stolen session is evicted the moment you recover the account.
  • Changing the email address on an account requires re-entering the current password, so a hijacked session alone cannot move the account to an attacker's inbox.
  • Passwords are stored as salted hashes. Nobody at DataFloat can read your password.

Third parties

Every company that touches your data

This is the complete list for your clients' financial data. If we add one, we will update this page. The handful of providers behind our marketing forms never see that data, and are named in our Privacy Policy.

ProviderWhat it doesLocation
FivetranMoves data from QuickBooks and HubSpot into your workspaceCanada (Montreal)
SupabasePrimary database where your synced financial data is storedUnited States (N. Virginia)
VercelHosts and runs the DataFloat applicationUnited States
AnthropicPowers the AI features that answer questions about your dataUnited States
IntuitSource of your QuickBooks accounting dataUnited States
HubSpotOptional CRM data source, only if you connect itUnited States
ResendSends account emails such as verification and password resetsUnited States
UpstashRate limiting to protect against abuse of our login endpointsUnited States
TavilyWeb search for market research features. Never receives your financial dataUnited States

Compliance

Where we stand today

DataFloat does not hold a SOC 2 certification. We are an early-stage company running a pilot.

The controls described on this page are real and implemented, but they have not been audited by an independent third party. If your firm requires SOC 2 attestation before adopting a vendor, we are not there yet. We would still like to hear from you, because knowing that requirement exists shapes when we pursue it.

Your data, your call

Disconnecting and deleting

You can disconnect a client's QuickBooks company from DataFloat at any time, and you can ask us to delete the data we have already synced.

Both are handled manually today, not through a self-serve button. Email us at security@datafloat.app and we will disconnect the integration, which stops all future syncing, and remove the synced data from our database. Self-serve versions of both are on our list, and this page will be updated when they ship.

Responsible disclosure

Found a security issue?

Report it to security@datafloat.app. We will acknowledge your report, keep you updated while we investigate, and we will not pursue legal action against researchers who report issues in good faith and give us a reasonable window to fix them.

Still have questions?

If your firm has a security review process or a question this page doesn't answer, we will answer it directly. No sales call required.