Security
AI Bookkeeper keeps each client's records isolated, logs every change in an append-only audit trail, and controls access per business. This page describes exactly how.
Per-client isolation
Every client's records live in a separate organization with its own access control — there is no shared pool of documents that a filter carves up. Each business you manage is its own set, with its own documents, its own contacts, and its own membership list.
Access is granted per business. Someone with access to one client's books sees nothing of another client's unless they are explicitly added to that organization too. If you run books for multiple clients, each stays in its own walled-off set.
Your data stays yours
Your documents are used to keep your books — that is the whole job. The bills, receipts and invoices you upload are read by OCR and a language model to extract vendor, totals, tax, dates and line items, and every extracted field links back to its highlighted location on your original document so you can verify where each value came from.
Because each business is isolated in its own organization, your documents are processed in the context of your books, not mixed into anyone else's.
What we can describe precisely is the architecture, so that is what this page does: isolated organizations, per-business access control, an audit trail that cannot be edited after the fact, and a clear account of what leaves our systems and why. Every claim on this page is something you can hold us to.
Every change is recorded
Every action on your books lands in an append-only audit trail — entries are added, never edited or deleted. Each approve or reject decision is recorded with a memo explaining why, alongside every correction made to an extracted field.
That means you can always answer the question 'who changed this, when, and why' — for the AI's extractions and human decisions alike. Documents that sailed through without a correction are traceable too: every extracted field keeps its confidence score and its link to the exact spot on the source document it came from.
Where an organization requires it, approval can be restricted so that whoever uploaded a document is not the person who signs it off.
Access control
Sign-in is via email/password or Google, handled through Clerk. Access to books is governed by role-based organization membership: what you can see and do depends on your role within each specific business.
There are no all-access accounts spanning every client by default. Membership is per organization, so adding a bookkeeper, an owner, or a reviewer to one business grants access to that business only.
Questions welcome
If you have a security question this page does not answer, email hello@aibookkeeper.com and we will give you a straight answer — including 'we don't have that yet' when that is the truth.
We are early-stage: pricing will be published at launch, no sales calls required. As the product matures, this page will grow with it — and it will only ever describe security measures that are actually in place. We would rather be short here than pad it.