Security Policy
Last updated: September 27, 2026
1. Scope
This policy covers Filebox Bookkeeping LLC systems and client data: the public website, the client portal, the client mailbox and receipt inbox, and the supporting infrastructure that operates them.
2. Access control
Access to client data and administrative systems follows least privilege: only the owner and the bookkeeping staff working on a given client's books can reach that client's data. Administrative access uses key-based authentication; shared passwords are not used. Credentials and API keys are stored outside public paths and are never placed in web roots or code repositories.
3. Network security
Our servers run a firewall that permits only the services customers need (HTTPS) plus administrative access. Databases are bound locally and are never publicly reachable. The public attack surface was penetration tested from an external host before launch, and findings were remediated and verified.
4. Data protection
All customer-facing traffic uses HTTPS with TLS, and HSTS is enforced. Client data resides in United States data centers with encrypted connections and limited access controls. Backups run on a scheduled basis with restore capability maintained.
5. Bank data
Bank data is read-only and is obtained only with the client's own consent, either through a secure aggregator flow the client approves themselves, or through files the client exports from their own bank. Filebox never asks for, receives, or stores online banking usernames or passwords.
6. Payments
Payments are processed by Stripe. Clients provide payment details directly to Stripe; Filebox never sees or stores full card numbers.
7. AI-assisted processing
Documents and transaction data are processed by AI services to categorize transactions. A Filebox bookkeeper reviews and approves every categorization before it enters the books. The AI services process data on our instruction and are contractually limited to that purpose.
8. Incident response
Any suspected breach is contained first (revoke access, isolate the system), then investigated, remediated, and reported to affected parties as required by law and by this policy.
9. Review and contact
This policy is reviewed at least annually and after any material change to systems or data handling. Questions or suspected issues: dave@fileboxbookkeeping.com or 833-FILEBOX (833-345-3269).