Security
How your numbers are handled, where they live, and who signs them.
Vouchwise is an AI-native accounting practice. The agents do the bookkeeping volume continuously; a licensed CPA reviews and signs every deliverable before it goes out. This page is the longer version of what that means for the data, the network, and the human at the end of the line.
- SectionIn transit
Encryption — at rest and in transit
Every number that moves through Vouchwise is encrypted on the wire and encrypted where it lives. Nothing is sent in the clear, nothing sits in plaintext, and nothing is logged in a way that would expose it.
- In transit: TLS 1.2+ between your browser and the app, between the app and Vouchwise systems, and between integrations (Plaid, Stripe, and similar) and the practice.
- At rest: Postgres disk-level encryption, object storage encrypted at rest, secrets injected at deploy — never bundled with the build, never logged.
- Per-tenant isolation in the application layer. Documents handed to CPAs are scoped to the engagement; nothing cross-pollinates between clients.
- SectionAt rest
Data residency
Your books stay in one place, on one side of one border. We do not split client records across regions or replicate them out-of-country, and we do not retain closed engagements longer than the law requires.
- Single region: US-only hosting. No cross-border copies of client numbers.
- Backups in-region, encrypted, time-bound. Restores happen from the same jurisdiction your books live in.
- Engagement-scoped retention: closed engagements are kept for the period required for tax and legal recordkeeping, then moved out of the active pipeline.
- SectionAccess
Role-based access via better-auth
Authentication in the app is the better-auth admin plugin. Default role is user; admin is reserved for the practice team. The framework-owned gate functions enforce that boundary, and revocations take effect immediately.
- Default role is user; admin is reserved for the practice team. The framework-owned requireAuth / requireAdmin helpers gate the dashboard and admin views.
- Clients do not sign in to receive deliverables — every closed book arrives as a signed PDF or report, addressed to you.
- Admin roles have scoped, audit-logged access to engagement data; revocations take effect immediately.
- Secrets (BETTER_AUTH_SECRET, DATABASE_URL, encryption keys) are deploy-injected — never present in the client bundle or build logs.
- SectionReview
CPA sign-off, reviewer credentials, and oversight
Every critical deliverable goes through a named licensed CPA on the Vouchwise practice before it leaves. The agents do the volume. The CPA carries the signature — and that signature is yours to verify on every output.
- Every controller-quality report, every tax return, and every filing packet is reviewed by a named licensed CPA on the Vouchwise practice before it is signed and sent.
- The reviewer is a US-licensed CPA — the firm license is held by the practice. The reviewer's name appears on every signed deliverable, and you can verify the signature on every return and report.
- Oversight runs continuously: agents do categorization, reconciliation, payroll, 1099, W-2, quarterly tax projections, and audit-ready workpapers — the CPA reviews and signs.
- Two-person rule on filings: a return ready to file is second-checked by a second CPA at the practice before it is submitted.
- Reviewer continuity: you keep the same CPA for the engagement — not a ticket in a queue.
Start
Talk to a CPA · open an intake.
One fee, one named CPA, every deliverable signed before it leaves the practice. Send a short note, or open the intake and the practice will reply the same business day.