Security

Security is not a feature we bolted on.

Tenant isolation, role-based permissions and a full audit trail are part of how every request is handled — not an afterthought.

Tenant isolation

Every table is scoped to your company. Every query checks it server-side — there is no client-side trust boundary to bypass.

Role-based permissions

Owner, Accountant, Controller, Approver, Viewer, and custom roles with granular permissions. A request without the right permission is rejected server-side — not just hidden in the interface.

Full audit trail

Every change to money, access, or configuration is logged: who, when, and what changed from and to.

Encryption

Passwords are hashed, never stored in plain text. Session tokens are randomly generated. Third-party integration tokens are encrypted at rest before they touch the database.

Closed periods stay closed

Once an accounting period is closed, no one — including an administrator — can post a new transaction into it without explicitly reopening it.

Infrastructure

Simplcor runs on Cloudflare's network. Data for this deployment is currently processed in the EU region.

The assistant never sees your credentials

OAuth connections and payment details are handled by the provider or platform directly — Simplcor's AI assistant never receives, stores, or types in a password or API key on your behalf.

See it for yourself.

Start free. No credit card required.

Start free trial