Security

Built like a system of record. Because it is one.

You're trusting an AI with your books, your bank connections, and your most sensitive IDs. Here's precisely how that's protected — down to the database — and the lines we won't cross with your data.

Guarantees

The rules are enforced by the ledger — not a policy page.

Six guarantees that hold because of how the system is built, not because we promise them.

Double-entry, enforced by the database

STRUCTURAL

Debits must equal credits — and the database itself rejects anything that doesn't balance. Your books can't silently drift out of integrity, even by accident.

An immutable, reversal-only ledger

APPEND-ONLY

Nothing is ever edited or deleted. A correction is a new reversing entry that leaves the original in place, so the full history is always there to inspect.

A complete audit trail

LOGGED

Every action — human or AI — is recorded with the actor, the change, and the timestamp. Who did what, when, and why, kept for good.

Strict per-tenant isolation

ISOLATED

Your data never shares a boundary with another company's. One tenant can't see or reach another's books.

Field-level encryption for sensitive IDs

ENCRYPTED

SSNs and EINs are encrypted at the field, not just on the disk — the most sensitive identifiers stay protected even inside the system.

Every AI decision on the record

REVIEWABLE

What the AI did, why it did it, and what the Auditor said about it — all logged and reviewable. The AI can't act off the books.

AI, controlled

AI you can audit — by design.

The real risk with AI accounting is a confident wrong answer nobody catches. Unfair CPA is built so that can't happen quietly.

Two agents, not one

The Bookkeeper posts the entry; the Auditor independently checks it. Agree → it posts. Disagree → it goes to your review queue. Mistakes are caught the moment they're made, not discovered at year-end.

You approve; the AI operates

The AI runs the books; it never owns them. Anything the two agents don't agree on waits for a human — you — before it touches your ledger.

Nothing happens off the record

Every decision, reversal, and disagreement is logged with its reasoning. You can always see exactly why your books say what they say.

Your data

Your data is yours.

You own your financial data — full stop. We hold it to run your books, and for nothing else.

  • We never use your data to train AI models. Your books are yours — they don't become anyone's training set.
  • We don't sell your data. What we collect and why is spelled out plainly in the Privacy Policy.
  • Ask us to access, export, or delete your data at any time — subject only to the record-keeping the law requires us to keep.
  • Every access to your books, by a person or the AI, lands on the same immutable audit trail described above.
Infrastructure

Certified infrastructure, encrypted end to end.

Unfair CPA runs on Cloudflare and Supabase — platforms independently audited to the standards your accountant will ask about.

SOC 2 Type II + ISO 27001

CERTIFIED

The platforms Unfair CPA runs on — Cloudflare and Supabase — are each independently certified to SOC 2 Type II and ISO 27001.

Encrypted in transit and at rest

ENCRYPTED

TLS on every connection and AES-256 at rest — plus field-level encryption for the most sensitive identifiers, like SSNs and EINs.

Automated backups

RECOVERABLE

Your data is backed up daily, with point-in-time recovery — so a bad day never means a lost ledger.

MFA + Google sign-in

AUTHENTICATED

Sign in with Google SSO and multi-factor authentication, so account access is protected by more than a password.

Found a vulnerability?

We take security reports seriously and investigate every one. Email [email protected] — and please give us a reasonable window to fix an issue before disclosing it publicly. We'll keep you posted.

Access

Invite-based today.

We onboard a small number of companies at a time, and we watch every ledger closely. Request access and we'll hold your place — or get a demo and watch a set of books run themselves.