Built like the books depend on it.
Two-factor authentication with any TOTP app, trusted devices so you are not challenged on every visit, a per-company IP allowlist with email approval for new locations, and a separate database for each company's data.
- TOTP two-factor for every user
- Trusted devices
- Per-company IP allowlist (Business)
- One isolated database per company
What you get
Authenticator-based two-factor sign-in for every user, an immutable audit log, and one isolated database per company.
How it works
- 1
Enrol 2FA
Scan the QR code with any TOTP app at first sign-in. Recovery is handled by an owner or admin, never by a weaker fallback.
- 2
Trust a device
Tick “trust this device” after a successful code. Trusted devices are listed with their last use and can be removed.
- 3
Set an allowlist
On Business: Settings → Security → IP allowlist. Add CIDR ranges, mark them permanent or temporary, and approve new locations by email.
- 4
Watch the log
Sign-in events and every data change are recorded in the immutable audit log for owners and admins to review.
Frequently asked
Is two-factor authentication mandatory?
Yes. Every user enrols an authenticator app at first sign-in; there is no SMS or email-only fallback. Trusted devices let you skip the challenge on a device you use daily.
Which plan includes the IP allowlist?
The per-company IP allowlist is part of the Business plan. Two-factor authentication, trusted devices, the audit log and per-company database isolation are on every plan.
What happens if I sign in from a new IP while the allowlist is on?
The sign-in is held and an approval email is sent. Approving it adds the address either temporarily or permanently — your choice — and the sign-in completes.
Where is my data stored?
In AWS in the EU (Frankfurt), in a database dedicated to your company, encrypted at rest and in transit. Files go to private per-company storage served through signed links.