Security
You are about to connect client bank feeds and accounting data to a tool. Here is exactly what that gives us access to, where it runs, and who else touches it.
Security at a glance
Bank access is read-only
Bank feeds arrive through Plaid using the transactions product. Equility can read history. It cannot move money.
You hold the keys
Every connection uses OAuth. Revoke Equility from QuickBooks or your bank and the sync stops that moment.
Encrypted in transit and at rest
TLS on every connection between your browser, our API and our services. Storage is encrypted on managed infrastructure.
Hosted in the United States
Our workloads run on Google Kubernetes Engine in us-central1. We do not operate our own data centres.
What each connection can actually do
Access is granted per integration and scoped to the job. Nothing below is implied consent for anything else.
Bank feeds
via Plaid- Reads
- Account balances and transaction history for the accounts you select.
- Writes
- Nothing. There is no payment or transfer capability in the product.
Your banking credentials go to Plaid, never to Equility. We receive a token, not a login.
QuickBooks Online
via Intuit OAuth- Reads
- Chart of accounts, general ledger and transactions for the periods you reconcile.
- Writes
- Only when you export a reconciliation, and only the entries shown to you in the export preview.
Revoke access from the Intuit app management screen at any time.
Commerce platforms
Shopify, Amazon- Reads
- Orders and payouts for the stores you connect, so deposits can be matched to their sources.
- Writes
- Nothing back to the store.
Only active if you connect a store. Nothing syncs by default.
Where it runs
Equility runs on managed Google Cloud infrastructure in us-central1. We do not operate our own data centres, and we do not replicate customer data outside that region.
Running a vendor review and need something not covered here, including the third parties we rely on? Email [email protected] and a human will answer it directly.
-
TLS protects every connection between your browser, our API and the services behind it.
-
Data is encrypted at rest on managed Google Cloud storage and managed PostgreSQL.
-
Records are scoped per company at the data layer, so one client's books are not reachable from another's session.
-
Sign-in runs through Firebase Authentication. We never store a password ourselves.
-
Staging and production are separate environments with separate credentials and separate data.
-
Application errors are captured in Sentry so failures surface to us rather than sitting silently.
Your data never trains someone else's model
Equility uses AI to suggest matches and account mappings. Here is precisely what that means for the data behind those suggestions.
Never sold, never someone else's training set. We do not license or sell your data, and we do not use it to train models for third parties. Equility may use de-identified or aggregated data derived from your documents to improve its own matching, and our models are not designed to memorise or reproduce a specific document. The full terms are in our Privacy Policy.
Some models never leave our infrastructure. Part of the matching stack runs on models we host ourselves. Where we do call an external model, it is the Google Gemini API.
A person approves every posting. AI proposes. Nothing reaches your general ledger until someone reviews it and exports it deliberately.
Keeping and deleting data
You decide how long we hold anything. Disconnecting is immediate, and deletion is a request away.
Disconnecting stops the sync
Revoke a bank or QuickBooks connection and Equility stops receiving new data immediately. Nothing is queued or retried behind the scenes.
Deletion on request
Email [email protected] and we will remove a company's synced data from our systems. Tell us which client and we will confirm when it is gone.
Uploaded documents stay yours
Statements and PDFs you upload are used to provide the service to you. We may draw anonymised or aggregated insight from them internally to improve accuracy, and nothing beyond that: they are never shared, sold or disclosed to third parties for marketing, analytics or advertising.
Found something?
If you believe you have found a vulnerability in Equility, tell us before you tell anyone else. We will acknowledge your report, keep you updated while we fix it, and credit you if you would like us to.
Your Next Close Is Already Counting Down
Every hour your team spends on manual reconciliations is an hour they're not doing higher-value work. Equility handles the matching, the checks, and the errors — so your close takes hours, not days.