FinAccrual

SECURITY

Security at FinAccrual

Last updated: September 20, 2026

FinAccrual is a product of Aveera LLC, an Ohio limited liability company. FinAccrual prepares accrual, prepaid, and deferred-revenue journal entries in Microsoft Excel and posts them to your accounting system. Because that means acting on your accounting data, this page explains plainly how the service is secured and — just as importantly — how little of your data we keep.

The short version: FinAccrual does not store your accounting records. Your chart of accounts, journal line items, and amounts are read into your own Excel workbook and posted directly to your accounting system. What we retain is a small set of references — enough to prevent duplicate postings and show you an audit trail — never the financial content itself.

1. What we store — and what we don't

Our database is deliberately minimal. It holds no journal amounts, no account balances, and no line-item detail.

DataStored?Why
Journal amounts, debits/credits, balancesNoNever written to our database
Chart of accounts, class/location listsNoPulled into your workbook only; not retained server-side
Line-item descriptions and memosNoNot retained
Your QuickBooks Desktop password or company-file credentialsNoThe connection is made locally on your computer, under QuickBooks’ own permission dialog
Your FinAccrual passwordNoHandled by Microsoft Entra External ID; we never receive it
Company ID, document number, resulting journal ID, posting status and timeYesDuplicate prevention and your posting history
A one-way hash of each entry's contentYesDetects re-posting of the same entry; the hash cannot be reversed into the underlying values
Your name and emailYesAccount identity and support
Authorization tokens for your accounting systemNoQuickBooks Desktop has no cloud token; see section 2
Company file identifier and name, and which users may post to itYesTies postings to the right file and enforces per-file access; see section 2

2. How the QuickBooks Desktop connection works

3. Encryption

4. Authentication and access control

5. Safeguards on posting

Because FinAccrual writes to your books, the risky operation is posting — so it carries specific controls:

6. Hosting and infrastructure

7. Monitoring

8. Data retention and deletion

9. Service providers

We rely on a small number of established providers to operate the service: Microsoft Azure (hosting, database, secret management), Microsoft Entra External ID (authentication), Stripe (subscription billing — card details are handled by Stripe and never reach our servers), QuickBooks Desktop runs on your own computer, so Intuit is not a service provider to FinAccrual and our servers never communicate with Intuit.

10. Reporting a vulnerability

If you believe you have found a security issue in FinAccrual, please report it to support@finaccrual.com with enough detail to reproduce it. We will acknowledge your report, investigate, and keep you informed of the outcome. Please give us a reasonable opportunity to remediate before any public disclosure, and avoid accessing or modifying data that is not your own while testing.

11. Honest scope

FinAccrual is an actively developed product from a small company. We describe above the controls that are actually in place; we do not claim certifications we do not hold. FinAccrual is not currently SOC 2 or ISO 27001 certified. If your organisation requires specific assurances or documentation, contact us and we will tell you plainly what we can and cannot provide today.

Questions about this page or our security practices: support@finaccrual.com
Aveera LLC · 4285 Morse Rd, PMB 17041798, Columbus, OH 43230 · See also our Privacy Policy and Terms of Service.