Security Policy

Last updated: 31 July 2026

1. Scope

This policy describes how Propte Pty Ltd (ABN 42 636 400 765) protects customer data in AccountMD, including the financial records we retrieve from the accounting systems our customers connect. It should be read alongside our Privacy Policy, which sets out what we collect and how long we keep it.

2. Data in transit

All traffic between your browser and our services, and between our services and third-party accounting APIs, is encrypted using TLS. We do not accept unencrypted connections.

3. Data at rest

Customer data is held in a managed PostgreSQL database that applies encryption at rest. The database has no public network address and is reachable only from our application over private networking. Our production systems run in Google Cloud's Sydney region (australia-southeast1).

4. Credentials and integration tokens

We never ask for, receive or store the username or password for your accounting system. Connections are established through the provider's own OAuth authorisation flow.

The access and refresh tokens issued by that flow are used only to retrieve data for the account that authorised them. Application passwords, where you use one, are stored only as salted one-way hashes and cannot be recovered by us. We also support passkeys and two-factor authentication, and we recommend using them.

API tokens and partner API keys are shown to you once at creation. We retain a short non-sensitive hint so you can identify a key in the interface, and logs are written to exclude credentials.

5. What we ask your accounting system for

We request the permissions the connection needs in order to read your records. We use that access to read only — we do not create, amend or delete anything in your accounting file — and the only write operation we perform against the provider is disconnecting our own access when you ask us to.

You can revoke our access at any time, either from within AccountMD or in your provider's own settings.

6. Access control

Within the application, access is enforced at the database itself through row-level security, not only in application code, so a user or connection can reach only the records they are authorised to see.

Access to production systems is limited to personnel who require it to operate or support the service, is protected by multi-factor authentication, and is granted on a least-privilege basis. Elevated database privileges are granted for specific maintenance operations and revoked afterwards. We are a small team, and the set of people with production access is correspondingly small.

7. Infrastructure and change management

We run on managed cloud infrastructure rather than self-managed servers, and rely on that provider for physical security, network isolation and patched host operating systems.

Changes reach production through an automated pipeline that runs linting, type checking and an automated test suite, and that blocks the deployment if they fail. Application dependencies are monitored for known vulnerabilities and updated.

8. What we hold, and for how long

Be aware that AccountMD stores a full copy of the accounting records you connect — including ledger postings, transactions, invoices and contacts — rather than summary figures only. That is what allows the service to report and analyse in detail, and it means the data we hold is as sensitive as your accounting file itself. We treat it accordingly.

We do not sell that data, do not disclose it to third parties for their own purposes, and do not use it to train machine-learning models. Retention, deletion and our backup-recovery caveat are described in the Privacy Policy.

9. Logging and monitoring

We log application and infrastructure events for operations and security investigation, and we filter those logs to exclude credentials and to minimise personal information. Administrative actions on our cloud resources are separately audit-logged.

10. Reporting a vulnerability

If you believe you have found a security vulnerability, please report it to security@propte.com. We will acknowledge your report, investigate, and keep you informed of the outcome. Please give us a reasonable opportunity to remediate before any public disclosure. We will not pursue action against researchers who report in good faith, act within the scope of their own account, and avoid privacy violations, data destruction and service disruption.

11. Incident response

If we become aware of a security incident affecting customer data, we will investigate promptly, take steps to contain and remediate it, and notify affected customers. Where an eligible data breach occurs we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).

12. What we do not claim

We are not currently certified against SOC 2, ISO 27001 or an equivalent standard, and we do not hold cardholder data — card details are entered directly with our payment processor and never reach our systems. We would rather tell you that plainly than imply assurances we have not obtained.

13. Contact

Propte Pty Ltd (ABN 42 636 400 765) — security@propte.com

AccountMD