CloseBooks

Security overview

How CloseBooks handles firm and client data.

CloseBooks is designed for CPA-firm workflows where financial data, client access, and review controls matter. This page summarizes the controls currently built into the product.

CloseBooks protects dashboard access with authenticated firm workspaces, subscription/trial gates, session controls, and review-first accounting workflows. We are intentionally transparent about what exists today and what is still part of the compliance roadmap.

Authentication and access

Dashboard routes require a signed-in user when Supabase authentication is configured. Email/password and Google sign-in are supported. Firm data is scoped to authenticated workspaces, and sensitive dashboard areas include role-aware controls.

Session controls

CloseBooks requires re-authentication after inactivity and exposes session visibility in firm settings. Middleware also applies security headers and rate limits selected public portal routes.

AI processing

AI categorization requests can include transaction descriptions, amounts, and the client chart of accounts so Claude can suggest categories. CloseBooks keeps a human review layer in the workflow: low-confidence or invalid account mappings remain in review before export.

Billing

Payment collection, invoices, and customer portal billing actions are handled by Stripe. CloseBooks does not store card numbers.

Compliance status

CloseBooks is not currently claiming SOC 2, ISO 27001, HIPAA, or similar third-party certification. Formal compliance programs are part of the roadmap as production firm usage grows.

Security contact

For security questions or responsible disclosure, contact security@closebooks.io.