Policies
Security Safeguards
Last updated: September 3, 2026
Liqod holds bank statements, ledgers and financial records belonging to businesses and their accountants. This page describes the technical and organisational safeguards we apply to protect that information, and the responsibilities that remain with you as the account holder.
1. Scope
These safeguards apply to the Liqod platform, its supporting infrastructure, and the personnel and vendors with access to it. They supplement our Privacy Policy and are subject to the disclaimers and limitations in our Terms of Service. This page is descriptive of our current controls and does not create a contractual warranty of any specific outcome.
2. Encryption
- All traffic between your browser and the Service is encrypted in transit using TLS 1.2 or higher.
- Customer Data, uploaded statement documents, cheque and receipt images, and database backups are encrypted at rest by our hosting infrastructure.
- Credentials are never stored in plain text; authentication secrets are hashed using industry-standard algorithms.
- Third-party API keys and service secrets are held in a managed secret store and are never exposed to the browser.
3. Access control and authentication
- Access to the Service requires an authenticated account. Password-based sign-in, one-time email verification codes and federated sign-in are supported.
- Multi-factor authentication is available and strongly recommended for every user, and is required for administrative access to our systems.
- Sessions expire after a period of inactivity, and idle sessions are signed out automatically.
- Internal administrative access follows least privilege: personnel receive only the access needed for their role, access is reviewed periodically, and it is revoked promptly on role change or departure.
4. Tenant and per-company isolation
- Every record in the platform is scoped to a company and a workspace, and row-level security rules are enforced server-side on every read and write.
- A user can only reach the companies they own, the companies assigned to them as a workspace member, or the companies shared with them as a read-only client.
- Team members invited to a workspace receive access only to the companies assigned to them at invitation time.
- Authorisation is enforced in the backend, not in the browser, so client-side manipulation cannot widen access.
- Every material action on a record is written to an immutable audit trail identifying the actor, the change and the time.
5. Infrastructure and network security
- The Service runs on managed cloud infrastructure operated in hardened, access-controlled data centres.
- Network controls, firewalling and environment segregation restrict access to production systems.
- Production, test and development data environments are kept separate.
- Server-side logging and monitoring are in place to detect errors, abnormal processing activity and abuse.
- Rate limiting and quota enforcement protect the platform against automated abuse.
6. Backups, resilience and recovery
- Customer Data is backed up on a regular schedule, with encrypted backups retained on a rolling cycle.
- Restore procedures are documented and periodically exercised so that recovery is not theoretical.
- Managed, redundant infrastructure is used to limit the impact of individual component failure.
- You can export your ledgers, reports and registers to Excel and PDF at any time, so you always hold an independent copy of your books.
7. Subprocessor oversight
We keep our vendor footprint deliberately small. Each subprocessor that may handle Customer Data — our hosting and database provider, our statement extraction provider, our payment processor and our transactional email provider — is engaged under contract with confidentiality and security obligations, is assessed before onboarding, and receives only the data required for its function. Card payment details are entered on the payment processor’s hosted checkout page and are never transmitted to or stored by Liqod. The current subprocessor list is set out in Section 5 of our Privacy Policy.
8. Secure development and vulnerability management
- Changes are reviewed before release, and server-side validation is applied to all input that affects stored records.
- Dependencies are monitored and updated to address known vulnerabilities, with security-relevant patches prioritised.
- Security defects are triaged by severity and remediated on a risk-based timeline.
- Independent security testing is part of our roadmap as the platform scales, alongside formal assurance reporting.
9. Incident response and breach notification
- We maintain an incident response process covering detection, triage, containment, eradication, recovery and post-incident review.
- Confirmed incidents affecting Customer Data are investigated promptly and escalated internally without delay.
- Where a personal data breach occurs, we notify affected customers without undue delay and, where we act as processor, provide the information you need to meet your own notification obligations — including the 72-hour requirement under the GDPR and applicable US state breach-notification laws.
- Where we act as controller, we notify the relevant supervisory authority as required by law.
10. Personnel
Personnel with access to production systems are bound by confidentiality obligations, receive security and data-handling guidance appropriate to their role, and are granted access only on a need-to-know basis. Access is logged and revoked promptly when no longer required.
11. Your responsibilities
Security is shared. To protect your clients’ financial data, you should:
- Enable multi-factor authentication on every user account, and use a unique, strong password.
- Invite team members with the narrowest company assignment that lets them do their work, and remove access promptly when someone leaves.
- Never share login credentials; create a separate Authorised User instead.
- Review the audit trail periodically and investigate activity you do not recognise.
- Verify extracted and categorised data before relying on it, as required by Section 6 of our Terms of Service.
- Keep your devices, browsers and email accounts secure, and treat unexpected requests for credentials as suspicious.
12. Reporting a vulnerability or suspicious activity
If you believe you have found a security vulnerability, or you notice unusual activity on your account, email security@liqod.com with enough detail for us to reproduce or investigate. Please give us a reasonable opportunity to remediate before public disclosure, and do not access, modify or exfiltrate data belonging to any other customer while testing. We will acknowledge legitimate reports and keep you informed of our progress.
Liqod will never ask you for your password. Suspected phishing messages claiming to be from Liqod should be forwarded to security@liqod.com and not acted upon.
13. Changes to this page
We update this page as our controls evolve. Material changes will be reflected here with a revised “Last updated” date.
