Security at TideOut

You are trusted with your clients' books. Here is how we look after the same data.

Where data is held

All application data and documents are stored in the United Kingdom (London region). We do not move client data outside the UK for storage.

Encryption

Data is encrypted in transit with TLS and encrypted at rest. Ledger access and refresh tokens are additionally encrypted at the application layer before they are written to the database.

Ledger tokens

Xero and QuickBooks tokens are never sent to the browser. Every call to a client's ledger is made from our servers, using the narrowest scopes the work requires.

Access and separation

Each firm's data is separated at the database level, so one practice can never read another's. Within a practice, access follows the role you give each member of staff.

Nothing posted without approval

TideOut writes drafts. Bills, coding changes and reconciliations only become live postings when a person approves them, and every approval is recorded in an append-only log you can export for your working papers.

Data processing agreement

A DPA is available on request, along with our sub-processor list. Email security@tideout.co.uk.

Back to TideOut