Security

Your Financial Data, Fully Protected.

Security isn't a feature we added — it's the foundation we built on. Every architectural decision starts with protecting your data.

AES-256 encryption at rest
TLS 1.3 in transit
SOC 2 aligned
Read-only API access

Six pillars of data protection

Bank-Grade Encryption

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Your financial data never travels unprotected.

Read-Only Access

CentSight connects to your financial systems with read-only permissions. We can see your data but never modify, move, or delete it.

SOC 2 Compliance

We're building toward SOC 2 compliance. Our infrastructure runs on Google Cloud Platform with enterprise-grade security controls from day one.

Data Minimization

We only collect the data necessary to provide financial intelligence. No unnecessary data harvesting, no selling to third parties, ever.

Role-Based Access

Control who sees what. Admins manage permissions, team members see only what they need, and audit logs track every access.

Regular Audits

We conduct regular security assessments and penetration testing. Our codebase undergoes continuous automated vulnerability scanning.

We can see your data. We can never touch it.

Every CentSight integration uses read-only API connections. We cannot initiate transactions, move funds, modify invoices, or alter any record in your accounting system. Ever. This isn't a policy choice — it's an architectural constraint. We literally cannot touch your money.

Security FAQ

Can CentSight move or delete my money?

No. CentSight uses read-only API connections. We can view your financial data to provide insights, but we have zero ability to initiate transactions, move funds, or modify records in your accounting systems.

Where is my data stored?

All data is stored in encrypted Google Cloud infrastructure in the United States. We use isolated, single-tenant database instances to ensure your data is never co-mingled with other customers.

Who can access my data within CentSight?

Only users you explicitly invite to your workspace. CentSight employees cannot access your financial data without your written permission, and all internal access is logged and audited.

What happens if I cancel my account?

All your data is permanently deleted within 30 days of account cancellation. We provide a full data export before deletion so you retain your records.

Have a security question?

We take security seriously and are happy to answer any questions about how we protect your data.