Security & Data Practices
A practical summary of how AccumIQ is designed to handle customer business data.
Least-privilege integrations
AccumIQ is designed to request only the access needed for a customer's configured workflows. Financial integrations are currently designed as read-only unless a separate write-enabled capability is expressly identified and approved.
Credential protection
OAuth tokens and other sensitive integration credentials are treated as secrets and are not intended to be displayed in application interfaces or support output. Where supported by the deployment, sensitive tokens are encrypted at rest.
Access controls and auditability
Customer workspaces use authenticated access and role-based controls. Integration activity and important administrative actions can be recorded for operational traceability and troubleshooting.
Source integrity
AccumIQ is designed to preserve source identifiers and timing differences so operational, invoicing, payment, and accounting events are not silently substituted for one another. This supports reconciliation and human review.
Data minimization
We aim to collect and retain the information reasonably needed to provide the configured Service. Customers should avoid placing unnecessary sensitive information into free-form fields or support messages.
Infrastructure and third parties
AccumIQ may rely on reputable hosting, database, identity, communications, and integration providers. Those providers have their own security responsibilities and terms. Third-party outages or platform changes can affect the Service.
Incident response
Suspected security incidents should be reported promptly to security@accumiq.ai. AccumIQ will investigate credible reports and coordinate appropriate containment, remediation, and customer communication based on the circumstances.
No unsupported certification claims
Unless separately documented in writing, this page does not represent that AccumIQ has obtained a particular third-party certification such as SOC 2 or ISO 27001.