Security & trust
This page states what is in place, what remains in progress, which providers may process data, and where to send a security report.
Core controls
Control detail can be provided through a security questionnaire during diligence.
Data is protected in transit and at rest. Connection tokens and sensitive configuration receive additional access controls.
Access checks scope users and requests to the appropriate firm, with role-based permissions for review and writeback workflows.
AI suggestions remain reviewable. Accounting changes are not written back without an authorized human decision.
Material review actions, approvals, conflicts, and writeback results are recorded with user and timestamp context.
AI data boundary
Customer accounting data is not used to train shared models or models for other customers. Corrections, learned rules, and tenant-specific configuration remain scoped to that customer.
Security testing
We perform ongoing internal security reviews and are building toward a formal independent penetration-testing program. We do not yet claim a completed annual penetration test.
Current providers
A provider receives data only when its related service is configured or enabled. Contract-specific details are available on request.
| Provider | Purpose | Data involved |
|---|---|---|
| Intuit QuickBooks | Accounting connection and sync | Authorized accounting records |
| Plaid | Bank-feed connection | Authorized account and transaction data |
| Google Gemini | AI-assisted suggestions and analysis | Relevant content for an enabled request |
| Clerk | Authentication and identity | User and session information |
| HubSpot | Demo requests and communications | Contact and workflow information |
| AWS | Cloud infrastructure and storage | Application and uploaded customer data where configured |
| PostHog / Google Analytics | Product or website analytics when enabled | Usage and device information |
| Stripe | Card billing when enabled | Billing and payment information |
Availability
SpeedReview does not currently publish an uptime SLA. Availability commitments, monitoring, and incident-response terms will be published before any SLA is offered.
Email the security contact with a clear description and reproduction steps. Please do not include live customer data.
Email the security contactNeed a DPA, security questionnaire, or roadmap context for vendor review?