Security and data protection

Your security review can start from ISO/IEC 27001:2022.

AccountKit is independently certified to the ISO/IEC 27001:2022 standard, hosts all customer data on AWS in Sydney, and makes two-factor sign-in mandatory for every user.

Certified
ISO/IEC 27001:2022
Hosted
AWS, Sydney
In transit
TLS 1.2 or higher
At rest
AES-256

Where the data goes

Follow your data from your accounting software to your document system, and see what guards each step.

Client data comes in from XPM and your ledger, the work happens in AccountKit, journals go back to your ledger and documents stay in your DMS. Choose a step to see its controls.

Your teamEveryone who signs in
Signing in to AccountKit2FA is mandatory for every userAuthenticator apps or SSO, and permissions your administrators set
Accounting and client managementXPM, Xero or QuickBooks
Client data in, journals backEncrypted in transit, TLS 1.2 or higherA connection your firm authorises
  • AES-256 encryption at rest
  • Hosted on AWS in Sydney
  • Audit logs and continuous monitoring
  • Point-in-time restore within 14 days
What protects the data here
Documents, both waysFiles stay in your document systemAccountKit doesn’t store them, and your DMS permissions still apply
Your DMSSharePoint, Google Drive or the system you use
Data coming inBack to your ledgerYour other apps

Controls, step by step

The published controls, grouped by the step they protect.

01Accounting and client management ⇄ AccountKit

Between your accounting software and AccountKit

  • All data in transit is encrypted using TLS 1.2 or higher.
  • Xero Practice Manager, Xero and QuickBooks are customer-authorised integrations: your firm chooses to connect them, and each provider processes data under its own terms.

02Inside AccountKit

While the data sits in AccountKit

  • Data at rest is encrypted using AES-256, and passwords and security data are securely hashed.
  • All customer data is hosted on AWS in Sydney, Australia, in a single region. AccountKit is built on the OutSystems platform, which runs on AWS.
  • Continuous monitoring for downtime, errors and access activity, with detailed audit logs and critical alerts escalated to engineering straight away.
  • Regular backups across multiple physical locations, with restore to specific points in time within a 14-day window.
  • Protections against common threats, including cross-site scripting (XSS) and SQL injection.
  • Regular penetration testing by independent global security specialists.

03AccountKit ⇄ your DMS

Between AccountKit and your document system

  • AccountKit doesn’t store your underlying documents. They remain in your document management system, such as SharePoint or Google Drive.
  • Permissions set in your DMS are respected: a user who can’t open a file in SharePoint can’t open it through AccountKit either.
  • Any other app that connects to the AccountKit API is assessed against the Security Standard for Add-on Marketplaces (SSAM), published by DSPANZ and the ATO, and reviewed every year.

04Who gets in

Who can reach the data

  • Multi-factor authentication is mandatory for every user, with authenticator apps and SSO available.
  • Your firm controls password policies and login methods, and administrators set what each user can see and do.
  • Access follows the principle of least privilege. Production access is limited to authorised AccountKit personnel, granted on operational need, and monitored and logged.
  • Vendors and contractors go through structured due diligence before engagement, scaled to the data involved.

Evidence for your file

What you can check for yourself, and where to get it.

Start with the Trust Centre. If your review needs something that isn’t listed here, email support@account-kit.com and the team will tell you what’s available.

  • ISO/IEC 27001:2022 certificate

    AccountKit is independently certified. Email support for a copy as part of your evaluation.

    Request a copy
  • Trust Centre documents

    The Information Security Policy, penetration test report, vulnerability assessment report and network diagram, available on request.

    Request access
  • Sub-processor list

    Every provider that may process personal data for AccountKit, from AWS and OutSystems to Twilio and Stripe. Last updated 2 August 2026.

    Read the list
  • Third-party integration requirements

    The SSAM-based standard every integration is assessed against, including breach reporting within 24 hours and an annual review.

    Read the requirements

Security questions

Straight answers to the questions reviewers ask first.

Is AccountKit independently certified?

Yes. AccountKit is independently certified as compliant with ISO/IEC 27001:2022, the information security management standard. Email support@account-kit.com for a copy of the certificate, or request the supporting documents through the Trust Centre.

Where is our data hosted?

All customer data is hosted on Amazon Web Services in Sydney, Australia, and isn’t spread across multiple regions. Data from UK and EU customers is processed in Australia under applicable transfer safeguards, including Standard Contractual Clauses.

Does AccountKit keep copies of our documents?

No. AccountKit doesn’t store your underlying documents. They stay in your document management system, such as SharePoint or Google Drive, and the permissions you set there still apply inside AccountKit.

Can a user turn off two-factor authentication?

No. Multi-factor authentication is mandatory for all users. Your firm can choose authenticator apps or SSO, and set its own password policy and login methods.

Who owns the data, and can we take it with us?

You retain full ownership of your data, and you can export it at any time.

How far back can data be restored?

Backups are kept across multiple physical locations, and data can be restored to a specific point in time within a 14-day window. Full system recovery procedures are in place as well.

How are other apps that connect to AccountKit checked?

Every integration that connects to the AccountKit API is assessed against the Security Standard for Add-on Marketplaces (SSAM), published by DSPANZ and the ATO. There’s no connection threshold, developers must report incidents within 24 hours, and each integration is reviewed once a year.

Ready for the detail

Bring your checklist, and we’ll help you work through it.

Request the documents in the Trust Centre, or book a demo to walk through the controls, hosting and access model with the team.