Your financial data, kept secure
Your books are among the most sensitive data your business has. We treat them that way. This page explains, plainly, how Reportly protects your data, who can access it, and what rights you keep.
Illustrative preview — not customer data
Encryption
All data is encrypted in transit using TLS 1.2 or higher. At rest, your data is encrypted with AES-256, the same standard used by banks and financial institutions. Encryption keys are managed separately from the data they protect and rotated on a regular schedule.
Access control
Only the people you invite can see your data, with the permissions you set. Internally, Reportly restricts production access to a minimal, audited set of engineers, granted on a least-privilege basis and only when required for support or reliability. Every access is logged, access is reviewed regularly, and it is revoked as soon as it is no longer needed.
Your data stays yours
Reportly never sells your data. Furthermore, your data is never used to train models for other customers. You can export everything at any time, and you can request full deletion.
Integrations security
Accounting connections use each provider's official authorization framework. Your credentials never pass through Reportly's servers. Additionally, you can revoke a connection instantly from either side. Details per connector live on the integrations pages.
Certifications and compliance
We follow GDPR principles for data protection, including data minimization, purpose limitation, and your right to access, export, and erase your data. Our infrastructure runs on established cloud providers whose data centers hold SOC 2 and ISO 27001 certifications. SOC 2 Type II certification for Reportly is in progress, and the report will be available on request once complete. See our privacy policy for the full legal detail.
Report a concern
Found a vulnerability or have a security question? Email security@reportlyai.com or contact us and flag it as security. A human reads every report, and we aim to acknowledge within two business days. We will not pursue legal action against researchers who report issues in good faith and give us reasonable time to respond.
We publish only what we can stand behind. Where a detail is still being finalized, it is marked to confirm rather than claimed. Real certifications and specifics will appear here as they are completed.
Security FAQ
See it on your own numbers
Reportly is in early access. Join the waitlist to get in first, with early-access pricing.