Security & data

How we protect your financial data

Manual2AI handles bills, supplier details and your Xero connection — for your business or, if you're a bookkeeper, for every client you look after. Here's exactly how that data is kept safe, in plain English. We describe only what the product does today.

Your books stay in your control

Manual2AI reads and writes to your Xero through a connection you authorise, and you can disconnect it at any time. Every bill keeps a complete, downloadable audit pack — the source document, the extracted data, and the approval history — so your records are portable and your own.

Workspaces are isolated

Each organisation's data lives in its own workspace. Access is checked on the server for every request against your membership — one customer can never see another's bills, vendors, or documents. The active-workspace selection is validated server-side, never trusted from the browser.

Role-based approvals + a full audit trail

Clerk, manager and admin permissions are derived and enforced on the server (never trusted from the client). Every action — capture, approval, payment, period lock — is written to an immutable, timestamped audit log that shows exactly who did what, including when someone acts on another's behalf.

Payment-fraud controls

When a supplier's bank details change, the bill is flagged and a payment run will not release to that supplier until someone explicitly verifies the new details. Duplicate invoices, PO mismatches and GST/ABN anomalies are caught and routed to review before anything is paid.

Encrypted in transit and at rest

All traffic is HTTPS with HSTS enforced. Data is held in managed PostgreSQL and documents in private object storage, encrypted at rest. A strict Content-Security-Policy with per-request nonces, plus standard security headers, harden the app against injection and clickjacking.

Hardened sign-in

You sign in with your own Manual2AI account — no third-party-branded login emails. Sign-in, password reset and password change are rate-limited against brute force, sessions are cryptographically signed and re-verified on every request, and you're alerted if your password is changed.

AI that only sees your data

Documents are read by Google's Gemini models to extract and code them. The built-in assistant answers only from your active workspace's live data — scoped by construction — and is strictly read-only: it drafts and suggests next steps, but it never approves, pays, or changes anything on its own.

Hosting

Manual2AI runs on Google Cloud, with a managed PostgreSQL database and private document storage. If your organisation has specific data-residency requirements, we want to hear them — see below.

Where we are

Manual2AI is an early-stage product. We haven't yet completed formal certifications such as SOC 2 or ISO 27001 — the controls above are what we operate today, and we'd rather tell you that plainly than imply otherwise. If your organisation has specific security or data-residency requirements, get in touch and we'll work through them with you.

Security questions or a vulnerability to report? support@manual2ai.com