Security

How your numbers are handled, where they live, and who signs them.

Vouchwise is an AI-native accounting practice. The agents do the bookkeeping volume continuously; a licensed CPA reviews and signs every deliverable before it goes out. This page is the longer version of what that means for the data, the network, and the human at the end of the line.

  1. Section
    In transit

    Encryption — at rest and in transit

    Every number that moves through Vouchwise is encrypted on the wire and encrypted where it lives. Nothing is sent in the clear, nothing sits in plaintext, and nothing is logged in a way that would expose it.

    • In transit: TLS 1.2+ between your browser and the app, between the app and Vouchwise systems, and between integrations (Plaid, Stripe, and similar) and the practice.
    • At rest: Postgres disk-level encryption, object storage encrypted at rest, secrets injected at deploy — never bundled with the build, never logged.
    • Per-tenant isolation in the application layer. Documents handed to CPAs are scoped to the engagement; nothing cross-pollinates between clients.
  2. Section
    At rest

    Data residency

    Your books stay in one place, on one side of one border. We do not split client records across regions or replicate them out-of-country, and we do not retain closed engagements longer than the law requires.

    • Single region: US-only hosting. No cross-border copies of client numbers.
    • Backups in-region, encrypted, time-bound. Restores happen from the same jurisdiction your books live in.
    • Engagement-scoped retention: closed engagements are kept for the period required for tax and legal recordkeeping, then moved out of the active pipeline.
  3. Section
    Access

    Role-based access via better-auth

    Authentication in the app is the better-auth admin plugin. Default role is user; admin is reserved for the practice team. The framework-owned gate functions enforce that boundary, and revocations take effect immediately.

    • Default role is user; admin is reserved for the practice team. The framework-owned requireAuth / requireAdmin helpers gate the dashboard and admin views.
    • Clients do not sign in to receive deliverables — every closed book arrives as a signed PDF or report, addressed to you.
    • Admin roles have scoped, audit-logged access to engagement data; revocations take effect immediately.
    • Secrets (BETTER_AUTH_SECRET, DATABASE_URL, encryption keys) are deploy-injected — never present in the client bundle or build logs.
  4. Section
    Review

    CPA sign-off, reviewer credentials, and oversight

    Every critical deliverable goes through a named licensed CPA on the Vouchwise practice before it leaves. The agents do the volume. The CPA carries the signature — and that signature is yours to verify on every output.

    • Every controller-quality report, every tax return, and every filing packet is reviewed by a named licensed CPA on the Vouchwise practice before it is signed and sent.
    • The reviewer is a US-licensed CPA — the firm license is held by the practice. The reviewer's name appears on every signed deliverable, and you can verify the signature on every return and report.
    • Oversight runs continuously: agents do categorization, reconciliation, payroll, 1099, W-2, quarterly tax projections, and audit-ready workpapers — the CPA reviews and signs.
    • Two-person rule on filings: a return ready to file is second-checked by a second CPA at the practice before it is submitted.
    • Reviewer continuity: you keep the same CPA for the engagement — not a ticket in a queue.

Start

Talk to a CPA · open an intake.

One fee, one named CPA, every deliverable signed before it leaves the practice. Send a short note, or open the intake and the practice will reply the same business day.