Your firm holds a lot of client information in AccountKit, so you'll want to know where it's kept and who can reach it. This article sets out what AccountKit publishes about its security, and where to get the documents for your own security review.
AccountKit is certified to ISO/IEC 27001:2022
AccountKit is independently certified as compliant with ISO/IEC 27001:2022, the international standard for information security management. You can email [email protected] for a copy of the certificate.
Where your data is stored
All customer data, including backups, is hosted on Amazon Web Services (AWS) in Sydney, Australia, in a single region. AccountKit is built on the OutSystems platform, which runs on AWS.
If your firm is in the United Kingdom or the European Union, your data is processed in Australia under transfer safeguards, including Standard Contractual Clauses. The data processing agreement sets out the detail, and the sub-processor list names every provider that may process personal data for AccountKit.
How your data is encrypted
Data travelling between your accounting software and AccountKit, and between AccountKit and your browser, is encrypted using TLS 1.2 or higher.
Data stored in AccountKit is encrypted using AES-256.
Passwords and security data are securely hashed.
Who can sign in and see your data
Two-factor authentication is mandatory for every AccountKit user, in every country. Your firm can sign in with an authenticator app or single sign-on (SSO).
Your firm sets its own password policy and login methods.
Your administrators decide what each user can see and do. On the Practice plan you can also use advanced permissions, including restricted access groups.
Inside AccountKit, access follows the principle of least privilege. Only authorised AccountKit staff can reach the production system, only when there's an operational need, and that access is monitored and logged.
Vendors and contractors go through due diligence before AccountKit engages them, scaled to the data involved.
What happens to your documents
AccountKit doesn't store your underlying documents. They stay in your document management system, such as SharePoint or Google Drive. The permissions you set there still apply, so a user who can't open a file in SharePoint can't open it through AccountKit either.
Monitoring, backups and testing
AccountKit is monitored continuously for downtime, errors and access activity, with detailed audit logs. Critical alerts go straight to the engineering team.
Backups are kept in AWS Sydney, across multiple physical locations, and data can be restored to a specific point in time within a 14-day window.
AccountKit is protected against common attacks, including cross-site scripting (XSS) and SQL injection.
Independent security specialists carry out regular penetration testing. You can request the latest penetration test report from the Trust Centre.
How other apps that connect to AccountKit are checked
Your firm chooses which integrations to connect, such as Xero Practice Manager and Xero, and each provider processes data under its own terms. Any app that connects to the AccountKit API is assessed against the Security Standard for Add-on Marketplaces (SSAM), published by DSPANZ and the ATO. Developers must report incidents within 24 hours, and each integration is reviewed every year. You can read the third-party integration requirements.
Who owns your data
Your firm keeps full ownership of its data, and you can export it at any time.
Getting the documents for your security review
The Trust Centre is where you request the Information Security Policy, the penetration test report, the vulnerability assessment report and the network diagram.
Email [email protected] for a copy of the ISO/IEC 27001:2022 certificate, or for anything your review needs that isn't listed here, and the team will get back to you.
The security page, the privacy policy and the data processing agreement are on the website.
