Trust & security
Nothing posts without approval. Nothing is locked in.
Accounting software holds the record a business runs on, so we hold it to a higher bar: every agent action reviewable and reversible, every approval logged, your data hosted in Canada and exportable at any time. Here is exactly how — and exactly where we are on the road to certification.
Our three commitments
01
AI you can audit
Agents propose entries. Your team approves them. An immutable log records who approved what, and why. No unsupervised posting of material entries — ever.
02
Your data stays in Canada
Production data lives in Canadian cloud regions, held by a Canadian-owned company. Residency alone isn't sovereignty — ownership is the other half.
03
Your books are always exportable
Full exports in standard formats, at any time, for any reason. Leaving must always be possible, or staying was never a choice.
Controls
AI you can audit
Most accounting AI asks you to trust a black box. Ours is built the way an auditor would design it: a strict separation between what the machine may suggest and what a human must approve, with a permanent record in between.
The control loop
01
Agents propose
Every entry an agent drafts arrives in a review queue with its source documents and its reasoning attached — the bank line, the invoice, the rule it applied. Proposals are exactly that: proposed, not posted.
Proposed
02
Your team approves
A named human accepts, edits, or rejects each proposal. Approval thresholds are configurable, so a routine recurring entry and a material adjustment never travel the same path.
Approved
03
Everything is logged
Each action lands in an append-only audit log: what was proposed, what changed, who approved it, and when. Entries are reversible through normal accounting means — a reversing entry, on the record — never by silent deletion.
Append-only
What our models will never do
No training on your data without consent
Customer books are never used to train models — ours or anyone's — unless you explicitly opt in, in writing. The default is no.
No unnamed “AI partners”
Every model provider we use is named in our subprocessor list, available on request. If a provider changes, the list changes, and customers are notified.
No agent access beyond its job
Agents operate under the same role-based permissions as people: an agent scoped to bank categorization cannot touch payroll journals, approvals, or exports.
Practices
Security practices
We are a young company, so we will tell you plainly what we do rather than borrow badges we haven’t earned. These are the practices in place today, built to the standard our SOC 2 program will formalize.
Encryption everywhere
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256), including backups.
Least-privilege access
Role-based access control for customers and staff alike; production access is limited to the engineers who need it, granted per task, and reviewed on a schedule.
No standing access to your books
Staff access to customer data requires a logged, purpose-stated grant — support access is something you can see, not something that just happens.
Single sign-on and MFA
Multi-factor authentication on all internal systems; SSO support for customer workspaces.
Segregated environments
Production, staging, and development are isolated; customer data never seeds a test environment.
Independent testing
Third-party penetration testing before general availability, and annually after — findings tracked to closure.
Vendor discipline
Every subprocessor is reviewed for security posture and data-handling terms before any customer data touches it.
Data residency
Hosted in Canada, owned in Canada
Production customer data is hosted in Canadian cloud regions. Backups stay in Canada too. For Canadian businesses — and especially for anyone subject to Quebec’s Law 25 or working near public procurement — where the data sits is not a nice-to-have; it is a compliance property.
But residency is only half the story. A US-owned vendor’s Toronto data centre is still reachable under the US CLOUD Act, because jurisdiction follows the owner, not the building. Eternify Labs is a Canadian company, based in Toronto, Ontario, Canada — Canadian-owned and Canadian-hosted. That combination is the strongest data-sovereignty position an accounting platform can offer Canadian businesses, and it is structural, not a marketing page.
Data sovereignty
- Residency
- Canadian cloud regions
- Ownership
- Canadian-owned, Toronto
- Jurisdiction
- Canada
Portability
The Portability Promise
Accounting software has a hostage-data problem: the harder it is to leave, the less the vendor has to earn your renewal. The industry saw where that ends when bookkeeping platforms have shut down with customers’ books inside. We think the only honest answer is to make leaving easy and permanent — in writing.
The commitment
- 01Your complete books — chart of accounts, journals, source documents, and audit log — are exportable in standard, machine-readable formats (CSV and structured exports), at any time, by you, without asking us.
- 02Export is a button, not a support ticket.
- 03If you cancel, your export access survives the cancellation for 90 days at no charge.
- 04If we ever wind down a product, we commit to a minimum 90-day notice period with full export support throughout.
- 05We will never charge a fee to give you your own data.
Your books are always exportable. Leave any time. That’s the promise, and it is unconditional.
Status
Where we are, honestly
Certifications are earned, not announced. Rather than imply a status we don’t hold, here is the current state of each — this section is updated as each milestone lands.
| Item | Status | What it means |
|---|---|---|
| SOC 2 | Program underway | We are building controls to the SOC 2 framework now, ahead of a formal audit. We do not hold a SOC 2 report today and won't claim one until an independent auditor issues it. |
| Penetration testing | Scheduled before GA | Independent third-party testing before general availability, then annually. |
| Regulatory certifications | Stated when granted | Where the product touches regulated processes, it is designed to the relevant standards. We hold no certifications today and will state each one here only when granted — never before. |
| Privacy (PIPEDA / Law 25) | Built to comply | Canadian residency, consent-based data use, and access logging are designed to meet PIPEDA and Quebec's Law 25 obligations. |
| Subprocessor list | Available on request | Current list of every subprocessor, including model providers, available by email. Published on this page at launch. |
Last reviewed: August 2026. If a status above looks out of date, tell us: k.parikh@eternifylabs.com.
FAQ
Questions accountants actually ask
Is my data used to train AI models?
No. Customer books are never used to train models — ours or a provider's — unless you explicitly opt in, in writing. The default is always no, and it never changes silently.
Can the AI post entries on its own?
No. Agents draft proposals; a named human approves, edits, or rejects each one before anything posts. Approval thresholds are configurable, and every decision is captured in an append-only audit log. There is no autonomous mode.
Where is my data hosted?
In Canadian cloud regions, including backups. Eternify Labs is also Canadian-owned, which matters: a foreign-owned vendor hosting in Canada remains subject to its home country's disclosure laws.
Are you SOC 2 certified?
Not yet, and we won't imply otherwise. Our SOC 2 program is underway — controls are being built to the framework ahead of a formal audit — and this page will state the report type and date the day we hold one.
What happens to my books if I cancel — or if you shut down?
They leave with you. Full exports in standard formats are self-serve at any time, export access survives cancellation for 90 days, and any product wind-down carries a minimum 90-day notice with export support throughout. See the Portability Promise above.
Who can see my books inside Eternify Labs?
Only engineers with a logged, purpose-stated access grant, scoped to the task and reviewed afterward. There is no standing staff access to customer data.
How do I report a security vulnerability?
Email k.parikh@eternifylabs.com with the details. Security reports go straight to the founder, and we respond to every one. We ask for reasonable disclosure time to ship a fix; we will never pursue good-faith researchers.
Ask us the hard questions.
Security reviews, subprocessor lists, data-processing terms — email the founder directly and get a real answer.