Skip to content
QB Systems

Security

We are asking for access to your books. Here is how we treat it.

Financial integration work means credentials to the systems that hold your money. The practices below apply to every engagement, and we will walk through them with your auditor, insurer or IT provider on request.

01 · Practices

AC

Access and credentials

  • Least-privilege access, requested per system and per engagement, revoked at close-out.
  • Client credentials held in a dedicated secrets manager, never in code, chat or spreadsheets.
  • Multi-factor authentication on every account we hold, including our own infrastructure.
  • Read-only access wherever a task does not require writing, which is most of them.
DH

Data handling

  • Production financial data stays in your environment wherever the work allows it.
  • Where a copy is unavoidable, it is minimised, encrypted at rest and in transit, and deleted on schedule.
  • Development and test environments use masked or synthetic data by default.
  • No client data is used to train, tune or evaluate any model.
DP

Development practice

  • Version control on everything, with reviewed changes and a traceable history.
  • Automated tests around calculation logic, run on every change.
  • Dependencies scanned and patched as part of the standing support agreement.
  • Separate development, staging and production environments with controlled promotion.
AR

Availability and recovery

  • Backups configured, encrypted, and restore-tested rather than assumed.
  • Monitoring that alerts on wrong figures, not only on downtime.
  • Documented runbooks so recovery does not depend on one person answering the phone.
  • Infrastructure defined as code, so an environment can be rebuilt rather than remembered.

02 · Controls at a glance

Encryption in transit
TLS 1.2 or above on every connection
Encryption at rest
AES-256 on managed storage and databases
Secrets
Managed secret store, rotated on personnel change
Audit logging
Application and infrastructure logs retained and reviewable
Change control
Peer-reviewed changes, staged releases, rollback path
Off-boarding
Access revoked and credentials rotated at engagement close

03 · Your obligations

If you carry a compliance obligation, we work inside it.

Clients come to us with audit requirements, payer contracts, lender covenants and client confidentiality agreements of their own. Tell us what you are bound by before the design phase and we will build the controls into the system rather than around it. Where a specific framework, agreement or attestation is required, ask and we will tell you plainly what we can and cannot sign.

Security questions, or a vendor questionnaire to complete? Send it to info@qbsystms.com.

Next step

Bring your questionnaire to the first call.

We would rather answer the security questions before the scoping questions. It usually makes the rest of the conversation shorter.