Fynease handles confidential financial data for controllers and fractional CFO practices. We take that responsibility seriously. Here is exactly how we protect it.
Every Fynease account operates in a strict multi-tenant environment with complete data isolation. Your client data is never accessible to other Fynease accounts, Fynease staff, or any third party — including any firm that builds on or integrates with Fynease. There are no shared data stores, no cross-client benchmarking that exposes individual client data, and no reporting that aggregates identifiable client information.
Fynease connects to QuickBooks Online via OAuth 2.0 — the same secure authorization standard used by QuickBooks Online integrations. Your QuickBooks Online credentials never pass through Fynease servers. You authorize the connection directly through Intuit's authentication flow, and you can revoke access at any time from your QuickBooks Online account settings.
All data transmitted between Fynease and QuickBooks Online, and between your browser and Fynease, is encrypted using TLS 1.2 or higher.
Server-side data is encrypted at rest at the infrastructure level. Fynease runs on Supabase (AWS), which applies AES-256 disk encryption to all stored data and backups. Database access is enforced through row-level security policies at the firm and engagement level — each firm's data is logically isolated and inaccessible to other accounts at the query layer.
Fynease enforces role-based access within each account. Account administrators assign Standard or Admin roles to team members, with access configurable at the client level. Row-level security in the database enforces firm and engagement isolation at the query layer — access controls are enforced by the database, not just the application. Financial mutations — every adjusting entry, schedule change, and consolidation adjustment — are written to an immutable append-only audit log. Fynease staff do not have access to customer data except as strictly required to diagnose a reported technical issue, and only with the account holder's explicit consent.
Fynease is hosted on enterprise cloud infrastructure with SOC 2 Type II certification. Our infrastructure provider maintains physical security, redundancy, and availability SLAs that meet the requirements of financial services workloads. Data is stored in Canada and the United States in compliance with applicable data residency requirements.
Acceptance of the Valuation Module Disclaimer is recorded per user, per client account, and per disclaimer version. Acceptance records include the user's name, email, organization, client account, disclaimer version, timestamp, browser user agent, and IP address. These records are stored in an append-only audit log, are not modifiable after creation, and are accessible only to Fynease for compliance verification. Acceptance records are retained for seven years following account cancellation.
Fynease uses the following subprocessors to deliver the service. We maintain data processing agreements with all subprocessors and require them to maintain security standards consistent with our own.
Fynease maintains a documented incident response procedure. In the event of a security incident affecting customer data, we will notify affected account holders within 72 hours of becoming aware of the incident, in accordance with applicable privacy legislation including PIPEDA and applicable provincial privacy laws.
If you have security questions or concerns, contact us at security@fynease.com. We respond to all security inquiries within one business day.