Trust & security
Nothing posts without approval. Nothing is locked in.
Accounting software holds the record a business runs on, so we hold it to a higher bar: every agent action reviewable and reversible, every approval logged, your data exportable at any time, and your data hosted in Canada from the first deployment. Here is exactly how, and exactly where we are on the road to certification.
Our three commitments
01
AI you can audit
Agents propose entries. Your team approves them. An immutable log records who approved what, and why. No unsupervised posting of material entries, ever.
02
Canadian-owned, data hosted in Canada
A Canadian-owned company, with partner data hosted in Google Cloud's Toronto region (northamerica-northeast2) from the first deployment, under contracts governed by Ontario law.
03
Your books are always exportable
Full exports in standard formats, at any time, for any reason. Leaving must always be possible, or staying was never a choice.
Controls
AI you can audit
Most accounting AI asks you to trust a black box. Ours is built the way an auditor would design it: a strict separation between what the machine may suggest and what a human must approve, with a permanent record in between.
The control loop
01
Agents propose
Every entry an agent drafts arrives in a review queue with its source documents and its reasoning attached: the bank line, the invoice, the rule it applied. Proposals are exactly that. Proposed, not posted.
Proposed
02
Your team approves
A named human accepts, edits, or rejects each proposal. Approval thresholds are configurable, so a routine recurring entry and a material adjustment never travel the same path.
Approved
03
Everything is logged
Each action lands in an append-only audit log: what was proposed, what changed, who approved it, and when. Entries are reversible through normal accounting means, a reversing entry on the record, never by silent deletion.
Append-only
What our models will never do
No training on your data without consent
Your books are never used to train models, ours or anyone's, unless you explicitly opt in, in writing. The default is no.
No unnamed “AI partners”
Every model provider we use is named in our subprocessor list, available on request. We have not yet selected the model provider; it will be named, with where it processes data, before any partner data reaches a model. If a provider changes, the list changes, and partners are notified.
No agent access beyond its job
Agents operate under the same role-based permissions as people: an agent scoped to bank categorization cannot touch payroll journals, approvals, or exports.
Practices
Security practices
We are a young company, so we will tell you plainly what we do rather than borrow badges we haven’t earned. These are the practices in place today, built to SOC 2 controls from the start and ahead of any audit.
Encryption everywhere
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256), including backups.
Least-privilege access
Role-based access control for partners and staff alike; production access is limited to the engineers who need it, granted per task, and reviewed on a schedule.
No standing access to your books
Staff access to partner data requires a logged, purpose-stated grant. Support access is something you can see, not something that just happens.
Multi-factor authentication
Required on our internal systems. Available on every account today and not yet required there; per-workspace enforcement is on the road to general availability.
Segregated environments
Production, staging, and development are isolated; partner data never seeds a test environment.
Independent testing
Third-party penetration testing planned before general availability, and annually after, with findings tracked to closure.
Vendor discipline
Every subprocessor is reviewed for security posture and data-handling terms before any partner data touches it.
Data residency
Owned in Canada, hosted in Canada
Partner data, backups included, is hosted in Google Cloud’s Toronto region (northamerica-northeast2) from the first deployment, and every design partner accepts that disclosure in writing before any data is connected. For Canadian businesses, and especially for anyone subject to Quebec’s Law 25 or working near public procurement, where the data sits is not a nice-to-have; it is a compliance property, and we would rather state it plainly than dress it up.
Three plain facts, then. Eternify Labs is Canadian-owned, based in Toronto, Ontario, Canada. The data is hosted in Canada. The contracts are governed by Ontario law. Google is a US-headquartered provider, so we do not describe hosting in Canada as immunity from foreign legal process; we describe it as what it is, and put it in the agreement rather than on a marketing page.
Data sovereignty
- Residency
- Google Cloud, Toronto
- Ownership
- Canadian-owned, Toronto
- Governing law
- Ontario
Portability
The Portability Promise
Accounting software has a hostage-data problem: the harder it is to leave, the less the vendor has to earn your renewal. The industry saw where that ends when bookkeeping platforms have shut down with customers’ books inside. We think the only honest answer is to make leaving easy and permanent, in writing.
The commitment
- 01Your complete books, chart of accounts, journals, source documents, and audit log, are exportable in standard, machine-readable formats (CSV and structured exports), at any time, by you, without asking us.
- 02Export will be a button, not a support ticket. Self-serve export is being built now; until it ships, an export is produced on request under the same terms, and no design partner connects data before it exists.
- 03If you cancel, your export access survives the cancellation for 90 days at no charge.
- 04If we ever wind down a product, we commit to a minimum 90-day notice period with full export support throughout.
- 05We will never charge a fee to give you your own data.
Your books are always exportable. Leave any time. That’s the promise, and it is unconditional.
Status
Where we are, honestly
Certifications are earned, not announced. Rather than imply a status we don’t hold, here is the current state of each. This section is updated as each milestone lands.
| Item | Status | What it means |
|---|---|---|
| SOC 2 | No report; no auditor engaged | Built to SOC 2 controls from the start. We do not hold a SOC 2 report and have not engaged an auditor; a penetration test is planned before general availability. We will state the report type and date here the day we hold one. |
| Penetration testing | Planned before GA | Independent third-party testing planned before general availability, then annually. |
| Regulatory certifications | Stated when granted | Where the product touches regulated processes, it is designed to the relevant standards. We hold no certifications today and will state each one here only when granted, never before. |
| Privacy (PIPEDA / Law 25) | Built to comply | Consent-based data use, access logging, and hosting in Canada are designed to meet PIPEDA and Quebec's Law 25 obligations. Privacy officer: Krutik Parikh, Founder. |
| Subprocessor list | Available on request | The current list is a schedule of the design-partner agreement and is available by email: Google Cloud in the Toronto region for compute, database, storage, queues, scheduling, secrets and logs; the AI model provider and the outbound email provider, both not yet selected. Published on this page at launch. |
Last reviewed: September 2026. If a status above looks out of date, tell us: k.parikh@eternifylabs.com.
FAQ
Questions accountants actually ask
Is my data used to train AI models?
No. Your books are never used to train models, ours or a provider's, unless you explicitly opt in, in writing. The default is always no, and it never changes silently.
Can the AI post entries on its own?
No. Agents draft proposals; a named human approves, edits, or rejects each one before anything posts. Approval thresholds are configurable, and every decision is captured in an append-only audit log. There is no autonomous mode.
Where is my data hosted?
In Canada: Google Cloud's Toronto region (northamerica-northeast2), backups included, from the first deployment. Google is a US-headquartered provider, so we describe this as data hosted in Canada under Ontario governing law, not as immunity from foreign legal process. Eternify Labs is Canadian-owned. The AI model provider is not yet chosen; every design partner is told in writing, by name, where model calls are processed before any data reaches a model.
Are you SOC 2 certified?
No. Built to SOC 2 controls from the start. We do not hold a SOC 2 report and have not engaged an auditor; a penetration test is planned before general availability. This page will state the report type and date the day we hold one.
What happens to my books if I cancel, or if you shut down?
They leave with you. Full exports in standard formats at any time are a term of the agreement (self-serve export is being built; until it ships, exports are produced on request), export access survives cancellation for 90 days, and any product wind-down carries a minimum 90-day notice with export support throughout. See the Portability Promise above.
Who can see my books inside Eternify Labs?
Only engineers with a logged, purpose-stated access grant, scoped to the task and reviewed afterward. There is no standing staff access to partner data.
How do I report a security vulnerability?
Email k.parikh@eternifylabs.com with the details. Security reports go straight to the founder, and we respond to every one. We ask for reasonable disclosure time to ship a fix; we will never pursue good-faith researchers.
Ask us the hard questions.
Security reviews, subprocessor lists, data-processing terms: email the founder directly and get a real answer.