Security
Last updated: June 16, 2026
Your financial data deserves bank-grade protection. Here is an overview of how we keep it safe.
Hosting & infrastructure
IPOPBOOKS runs on Amazon Web Services (AWS). We rely on AWS’s secure, SOC 2-compliant infrastructure for hosting, networking, and managed databases, with isolation between environments.
Encryption
- In transit — all traffic is encrypted with TLS (HTTPS).
- At rest — data stored in our databases and backups is encrypted.
- Sensitive identifiers are additionally encrypted at the application layer.
Bank connections
We connect to your financial accounts through our aggregation provider (Quiltt and its underlying providers). Connections are token-based and read-only — IPOPBOOKS never sees or stores your online banking password, and we cannot move money. You can disconnect a bank at any time from your account settings.
Access controls
- Access to production systems and customer data is restricted on a least-privilege, need-to-know basis.
- Sensitive data is never exposed in API responses, and access is logged.
- Your dedicated bookkeeper sees only the data needed to keep your books.
Monitoring & resilience
We monitor our systems for availability and suspicious activity and maintain encrypted backups so your data can be recovered.
Responsible disclosure
If you believe you’ve found a security vulnerability, please email support@ipopbooks.com with the details. We appreciate responsible disclosure and will work with you to resolve verified issues promptly.
Contact
Questions about our security practices? Reach us at support@ipopbooks.com.