Security
How we look after your books
Each business's data stays separate
Every record belongs to one business, and the database itself enforces that with row-level security: a request working for one business can't read another's rows, even if our application code had a mistake.
Sensitive data is encrypted
Connections use HTTPS. Bank, QuickBooks and calendar access tokens and contractors' taxpayer ID numbers are encrypted in our database with keys kept separately from it. We never see or store your bank login; bank connections go through Plaid, and card payments through Stripe.
Signing in
Passwords are hashed, never stored. You can add passkeys and two-step verification (an authenticator app). Sign-in attempts are rate-limited.
Nothing moves without you
RiverBooks and River, the assistant, suggest; you approve. Nothing pays anyone, files a return or changes your books on its own, and every change is recorded in your business's audit log with who made it.
Support access
When you ask for help, RiverBooks staff can view your books read-only for up to an hour, with the reason recorded in your audit log. Staff can't change your records.
Backups
Our database host keeps backups, and we are adding our own encrypted nightly copies with a separate provider, restored on a schedule to prove they work.
Found a problem?
Please tell us at security@riverbooks.ai. We'll reply, fix it, and credit you if you like.