Built like the books depend on it.

Two-factor authentication with any TOTP app, trusted devices so you are not challenged on every visit, a per-company IP allowlist with email approval for new locations, and a separate database for each company's data.

  • TOTP two-factor for every user
  • Trusted devices
  • Per-company IP allowlist (Business)
  • One isolated database per company

What you get

Authenticator-based two-factor sign-in for every user, an immutable audit log, and one isolated database per company.

Two-factor, not optional

Every user enrols an authenticator app (Google Authenticator, 1Password, Authy…) at first sign-in. A password alone never opens a company's books.

Trusted devices, your call

Mark a laptop as trusted and skip the code on that device for a while. Review and revoke devices any time from Settings → Security.

IP allowlist with approvals

Business companies can restrict sign-in to office or VPN ranges. A sign-in from a new address emails an approval link, so a travelling owner is never locked out.

Isolation by design

Each company has its own database — not a shared table with a tenant column. Encryption in transit and at rest, HSTS and a strict Content Security Policy on every page.

How it works

  1. 1

    Enrol 2FA

    Scan the QR code with any TOTP app at first sign-in. Recovery is handled by an owner or admin, never by a weaker fallback.

  2. 2

    Trust a device

    Tick “trust this device” after a successful code. Trusted devices are listed with their last use and can be removed.

  3. 3

    Set an allowlist

    On Business: Settings → Security → IP allowlist. Add CIDR ranges, mark them permanent or temporary, and approve new locations by email.

  4. 4

    Watch the log

    Sign-in events and every data change are recorded in the immutable audit log for owners and admins to review.

Frequently asked

Is two-factor authentication mandatory?

Yes. Every user enrols an authenticator app at first sign-in; there is no SMS or email-only fallback. Trusted devices let you skip the challenge on a device you use daily.

Which plan includes the IP allowlist?

The per-company IP allowlist is part of the Business plan. Two-factor authentication, trusted devices, the audit log and per-company database isolation are on every plan.

What happens if I sign in from a new IP while the allowlist is on?

The sign-in is held and an approval email is sent. Approving it adds the address either temporarily or permanently — your choice — and the sign-in completes.

Where is my data stored?

In AWS in the EU (Frankfurt), in a database dedicated to your company, encrypted at rest and in transit. Files go to private per-company storage served through signed links.

Browse all features →

Ready to run cleaner books?

Open Nefin in minutes. No credit card required.