Last updated: 31 July 2026
This policy describes how Propte Pty Ltd (ABN 42 636 400 765) protects customer data in AccountMD, including the financial records we retrieve from the accounting systems our customers connect. It should be read alongside our Privacy Policy, which sets out what we collect and how long we keep it.
All traffic between your browser and our services, and between our services and third-party accounting APIs, is encrypted using TLS. We do not accept unencrypted connections.
Customer data is held in a managed PostgreSQL database that applies encryption at rest. The database has no public network address and is reachable only from our application over private networking. Our production systems run in Google Cloud's Sydney region (australia-southeast1).
We never ask for, receive or store the username or password for your accounting system. Connections are established through the provider's own OAuth authorisation flow.
The access and refresh tokens issued by that flow are used only to retrieve data for the account that authorised them. Application passwords, where you use one, are stored only as salted one-way hashes and cannot be recovered by us. We also support passkeys and two-factor authentication, and we recommend using them.
API tokens and partner API keys are shown to you once at creation. We retain a short non-sensitive hint so you can identify a key in the interface, and logs are written to exclude credentials.
We request the permissions the connection needs in order to read your records. We use that access to read only — we do not create, amend or delete anything in your accounting file — and the only write operation we perform against the provider is disconnecting our own access when you ask us to.
You can revoke our access at any time, either from within AccountMD or in your provider's own settings.
Within the application, access is enforced at the database itself through row-level security, not only in application code, so a user or connection can reach only the records they are authorised to see.
Access to production systems is limited to personnel who require it to operate or support the service, is protected by multi-factor authentication, and is granted on a least-privilege basis. Elevated database privileges are granted for specific maintenance operations and revoked afterwards. We are a small team, and the set of people with production access is correspondingly small.
We run on managed cloud infrastructure rather than self-managed servers, and rely on that provider for physical security, network isolation and patched host operating systems.
Changes reach production through an automated pipeline that runs linting, type checking and an automated test suite, and that blocks the deployment if they fail. Application dependencies are monitored for known vulnerabilities and updated.
Be aware that AccountMD stores a full copy of the accounting records you connect — including ledger postings, transactions, invoices and contacts — rather than summary figures only. That is what allows the service to report and analyse in detail, and it means the data we hold is as sensitive as your accounting file itself. We treat it accordingly.
We do not sell that data, do not disclose it to third parties for their own purposes, and do not use it to train machine-learning models. Retention, deletion and our backup-recovery caveat are described in the Privacy Policy.
We log application and infrastructure events for operations and security investigation, and we filter those logs to exclude credentials and to minimise personal information. Administrative actions on our cloud resources are separately audit-logged.
If you believe you have found a security vulnerability, please report it to security@propte.com. We will acknowledge your report, investigate, and keep you informed of the outcome. Please give us a reasonable opportunity to remediate before any public disclosure. We will not pursue action against researchers who report in good faith, act within the scope of their own account, and avoid privacy violations, data destruction and service disruption.
If we become aware of a security incident affecting customer data, we will investigate promptly, take steps to contain and remediate it, and notify affected customers. Where an eligible data breach occurs we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).
We are not currently certified against SOC 2, ISO 27001 or an equivalent standard, and we do not hold cardholder data — card details are entered directly with our payment processor and never reach our systems. We would rather tell you that plainly than imply assurances we have not obtained.
Propte Pty Ltd (ABN 42 636 400 765) — security@propte.com