Security & trust

Your financial data, seriously protected.

XpressBooks handles some of the most sensitive data a business has. We protect it with encryption, strict access controls, and vetted infrastructure — and we hold ourselves to the same standards internally.

Encryption everywhere

  • At rest: all customer data encrypted with AES-256.
  • In transit: every connection uses TLS 1.2 or higher; HTTPS is enforced everywhere.
  • Secrets: API keys and credentials live in a secured secrets store — never in our source code.

Strict access control

  • Row-Level Security isolates every account in the database — you can only ever access your own data.
  • Multi-factor authentication is required for all administrative access.
  • Least privilege and role-based access, with access reviews conducted regularly.
  • Audit logging on authentication, data access, and configuration changes.

What we store — and what we never touch

What we store (encrypted)

  • Bank connections via Plaid read-only tokens (encrypted)
  • Transaction history & balances (encrypted at rest)
  • Your name and email
  • Payment tokens (via Stripe — never full card numbers)

What we never store

  • Your bank username or password
  • Full credit card numbers
  • Social Security numbers
  • Government-issued ID numbers

Bank connections are powered by Plaid using read-only tokens. Your banking credentials are entered with Plaid and never reach XpressBooks. And we never sell or rent your data — to anyone.

Vetted infrastructure

We build on providers that meet rigorous, independently audited security standards. Every vendor that touches customer data is required to maintain SOC 2 Type II certification (or equivalent) and encrypt data at rest and in transit.

Provider Purpose Standard
Supabase Database & authentication SOC 2 Type II · AES-256
Vercel Application hosting & edge network SOC 2 Type II · DDoS protection
Stripe Payment processing PCI DSS Level 1
Plaid Bank connectivity (read-only tokens) SOC 2 Type II
Resend Transactional email SOC 2

Resilience & incident response

  • Continuous backups with point-in-time recovery.
  • Documented incident response with defined containment, eradication, and recovery steps.
  • Breach notification to affected customers within 72 hours of a confirmed incident.

Your data, your rights

You can access, correct, export, or delete your data at any time. On account closure, bank tokens are revoked within 24 hours and your financial data is permanently deleted within 30 days (aside from records we’re legally required to retain). Our practices are designed to honor CCPA, GDPR, and GLBA, and align with the NIST Cybersecurity Framework, SOC 2, and OWASP guidelines.

Questions, or found something?

Reach our security team at security@xpressbooks.ai. We take every report seriously.

Get early access