Is your financial data secure? How Reportly protects it
Key takeaways
- Reportly's accounting connection is read-only: it cannot move money, create transactions, or alter your QuickBooks records.
- Data is encrypted in transit and at rest.
- Access inside your workspace is role-based.
- SOC 2 Type II audit is underway; we name only what's verified.
- If you leave, you can export your data and request deletion, on a defined timeline.
What Reportly accesses, and what it doesn't
The fear worth addressing first isn't hacking; it's scope. What can this tool actually do with my books?
The answer is structural. Reportly connects to QuickBooks through OAuth with read-only scope, which means the permission grant itself, issued and enforced by Intuit, does not include writing. Reportly cannot move money, create or edit transactions, change your chart of accounts, or alter anything in your books, not because of a policy we promise to follow, but because the connection doesn't carry those permissions in the first place. Your QuickBooks credentials are never entered into Reportly; the authorisation happens on Intuit's own pages.
What Reportly reads: your chart of accounts, transaction-level P&L and balance sheet data, and nothing beyond what the authorisation screen lists. The setup flow shows the requested scopes at authorisation, so you can see the boundary yourself; how the connection is made step-by-step is in our QuickBooks setup guide.
Encryption
Plain language first: your data is unreadable in transit between your browser, Reportly, and QuickBooks, and unreadable at rest on disk, to anyone without the keys.
The specifics alongside: transport encryption is TLS, the same family of protocols protecting online banking sessions, and data at rest and backups are encrypted to the same standard. We deliberately avoid the phrase "bank-level encryption" because it's marketing, not a specification; if your review needs the exact protocol versions and key-management details, contact us and we'll provide them in writing.
Access controls
Three layers control who sees your numbers.
Authentication. Accounts are protected by authenticated sign-in. If two-factor authentication or SSO matters to your team, contact us for the current status before relying on it.
Roles. Within your workspace, access is role-based, so your bookkeeper, your co-founder, and a board observer can be given different levels of visibility rather than all-or-nothing access.
Sessions and logging. Sessions expire automatically rather than living forever. An audit trail matters most on the day something looks odd, which is exactly when you don't want to discover it doesn't exist, so ask us where logging stands for the actions you care about.
Where your data lives
Your data is hosted on major cloud infrastructure, and where it lives determines the legal framework around it, especially for European customers. Rather than answer that in vague terms, we confirm hosting region, residency options, and our GDPR posture in writing: contact us and we'll put the specifics on paper.
Compliance and standards
Only what's verified, with status:
- SOC 2 Type II: audit underway. We'll publish the report status here when it completes. (A Type II report covers controls operating over time, which is why it takes longer than a point-in-time Type I.)
- GDPR: we confirm our current posture and DPA availability in writing on request.
A note on why this list is short: an unsupported compliance claim isn't marketing, it's misrepresentation, and vendors who round "in progress" up to "certified" are telling you something about how they'll handle your data too. We'd rather show a dated audit-in-progress than an adjective.
What happens if you leave
The exit terms are part of security, and they're rarely stated, so here are ours.
You can disconnect the QuickBooks connection at any time, from either side, and cancel your account without a retention lock-in. Before or after cancelling, you can export your data. After cancellation, your data is deleted from production systems and backups on a defined timeline, and you can request expedited deletion. Your books, of course, remain untouched in QuickBooks throughout; Reportly holds a copy of reporting data, never the system of record.
Security questions before you connect? Ask us anything, in writing.
Questions to ask any financial software vendor
Use this checklist on us and on every competitor. A vendor who answers all seven crisply is telling you something; so is one who doesn't.
- Is the accounting connection read-only? Show me the OAuth scopes.
- What encryption do you use in transit and at rest? Name the protocols, not adjectives.
- Who at your company can access my data, and under what controls?
- Do you support two-factor authentication, and can I enforce it for my team?
- Where is my data hosted, and which legal framework applies?
- What certifications do you hold, and can I see the reports? If something's "in progress," what's the date?
- If I cancel, how do I get my data out, and when is it deleted, including from backups?
Frequently asked questions
Is it safe to connect QuickBooks to third-party software?
With a read-only OAuth connection to a vendor with real encryption and access controls, the added risk is low and the boundary is enforced by Intuit, not just promised by the vendor. The checklist above tells you how to judge any specific tool.
Can Reportly move money or change my books?
No. The connection is read-only, so Reportly cannot create transactions, edit records, or touch anything in QuickBooks; data flows one direction only.
Where is my data stored?
On major cloud infrastructure. If you have data-residency requirements, contact us and we'll confirm specifics in writing.
Who at Reportly can see my data?
Internal access is restricted to what support and operations require. No one at Reportly has a reason or a route to browse customer financials casually.
What happens to my data if I cancel?
You can export it first, and it's deleted from production and backups on a defined timeline. Your QuickBooks file is unaffected either way.
If your security review has questions this page doesn't answer, talk to us; written answers, including our current audit status, are part of what we consider normal pre-sales work. The full list of data connections is on the integrations page.