Single Platform For The Whole Set Of Books

Trust

Security, Described Plainly

Books are somebody's business. This page describes what protects them — isolation, a tamper-evident audit trail, access control and the right to take everything back — in terms you can check rather than a list of badges.

Isolation

One Schema Per Business

Every business gets its own Postgres schema, and every query runs inside a transaction bound to that business. A query with no business context does not fall back to a shared table — it finds nothing, which is the correct answer.

Isolation

Database-Level Enforcement

Above the application boundary sits a second one: row-level security with per-tenant database roles, so isolation does not depend on the application asking nicely.

Audit trail

Chained, Not Just Logged

Each audit row hashes its own contents together with the previous row's hash. Editing a row, deleting one, or re-ordering the sequence breaks the chain from that point on — which is what the MCA mandate means by tamper-evident.

Audit trail

Cannot Be Switched Off

There is no setting that disables it, because the Companies (Accounts) Rules do not permit one. Chain state is anchored periodically and any tamper is raised as a security event.

Access

Two-Factor, Lockout, Allowlist

TOTP two-factor, automatic lockout on repeated failures, and an optional IP allowlist per business — so a firm can restrict access to its own office network.

Access

Every Event Recorded

Sign-ins, failures, lockouts, two-factor changes, password changes and blocked requests are all written to a security log you can read.

Data

Yours To Take Back

Masters, vouchers and balances export in full, at any time, in a format Tally reads. Leaving is a download, not a negotiation.

Data

Yours To Erase

A business can be erased on request — completely, including its schema — which is what the DPDP Act's erasure right requires in practice rather than in a policy document.

Consent

Recorded, With The Version

Acceptance of terms and privacy is recorded as evidence, along with which version was accepted. A policy that changed after you agreed to it is not evidence of anything.

AI

Provenance On Every Suggestion

Where AI reads a document, what it produced is stored with what it read and which model produced it. Nothing posts to your books without a person confirming it.

The audit trail, in detail

Why Chaining Matters

A log that records changes proves nothing on its own, because whoever can write to it can usually edit it. The MCA mandate asks for something stronger: a record that shows if it has been altered.

Every audit row is hashed together with the previous row's hash, so each row binds to the one before it. Change a value in row 400 and its hash no longer matches; delete row 400 and row 401 no longer points at anything; re-order two rows and both break. The chain does not prevent tampering — nothing can — it makes tampering visible, which is the property an auditor needs.

What an auditor can do with it

Ask for the chain to be verified for a period. Either every row's hash reproduces, or the report names the exact rows that do not. That is a much shorter conversation than reading a log and hoping.

Chain state is anchored periodically so the sequence cannot be silently rebuilt from scratch, and a failed verification raises a security event rather than sitting in a file nobody opens.

Security Questions

Where is our data stored?
On managed Postgres infrastructure with automated backups and point-in-time recovery. If your engagement requires a specific region, ask us before you sign — not after.
Can Autobooks staff see our books?
Access to production data is restricted and logged. Support cannot read a business's books without access being granted, and the grant is recorded in the same audit trail you can read.
What happens if we stop paying?
You keep the ability to export. Books do not become hostage to a subscription — the export path is the same one you would use on any other day.
Is the audit trail actually MCA-compliant?
It is built to the Rule 3(1) proviso: recorded for every change, not disableable, and tamper-evident through hash chaining. Whether your specific engagement is compliant is a question for your auditor, and the trail is designed to be shown to one.
Do you train AI models on our data?
No. Documents are processed to produce a result for your business, with provenance stored against that result.
How do you handle a breach?
Affected businesses are notified along with what was accessed and what we did. The security event log means we can say what happened rather than what we believe happened.

Read Next