Access Control Policy

Last updated: September 27, 2026

1. Purpose and scope

This policy defines how Filebox Bookkeeping LLC limits access to its production systems and client data. It covers the public website, the client portal, the client mailbox and receipt inbox, supporting infrastructure, and all client financial information.

2. Principles

Access follows least privilege: a person or system receives only the minimum access needed to perform its function, and only for as long as it is needed. Client data is separated per client, so no one working on one client's books can reach another client's data without explicit authorization.

3. Human access and authentication

Administrative access to production systems is limited to the owner and bookkeeping personnel with assigned duties. Administrative access uses key-based authentication; shared or reused passwords are prohibited. The portal separates each client into its own company with role-scoped users: administrators manage settings, bookkeepers work the books, and no role receives more capability than its duties require.

4. Non-human access

System-to-system access uses OAuth tokens or TLS certificate authentication. Bank data connections are created only through a client-approved OAuth flow and are read-only. Payment APIs authenticate with account-scoped keys over encrypted connections. Service credentials are stored outside public paths, are never placed in web roots or code repositories, and are rotated immediately if a compromise is suspected.

5. Network and system boundaries

Production servers run a firewall that permits only required services. Databases are bound locally and are never publicly reachable. Client-facing traffic uses HTTPS with TLS, and HSTS is enforced.

6. Access reviews and deprovisioning

Access rights are reviewed at least annually and after any material change to systems, staffing, or client scope. When a person leaves a role or a client ends service, their access is revoked promptly, and credentials or keys they could have used are rotated. Access changes are documented and verifiable.

7. Logging and accountability

Operational logs record administrative and application events and are retained for review. Suspicious access activity is investigated under the incident response process in the Security Policy.

8. Enforcement and contact

Violations of this policy result in immediate suspension of the affected access and review by the owner. Questions or suspected issues: dave@fileboxbookkeeping.com or 833-FILEBOX (833-345-3269).