Security

The architecture: a relay, not a warehouse

Caribooks bridges your AI assistant and QuickBooks Online. Your accounting data travels encrypted and is never retained: no invoice, no journal entry, no financial figure is saved in our databases. What we don't keep can't leak.

What we do keep, and how

Three things: your account email, the names of your connected companies, and your QuickBooks access tokens, encrypted with AES-256-GCM. Everything is hosted in Canada, in the AWS Montréal region. Payments run through Stripe; card numbers never touch our servers.

A token, never your password

Connecting a company goes through the standard Intuit authorization (OAuth). Intuit hands us a token that only opens your books; we never see your QuickBooks password. You can revoke that token at any time, from the Caribooks portal or directly with Intuit, and access dies immediately.

Read-only by default

A connected company starts read-only: the assistant looks, nothing moves. Write access is enabled company by company, by you alone, and every delete requires an explicit confirmation in the conversation.

Passwordless sign-in

Your Caribooks account opens with a magic link sent to your email. No Caribooks password exists, so there's no password to steal.

Your books don't train the models

Anthropic excludes MCP connector content like Caribooks from training on every plan. On ChatGPT, Business, Enterprise and Edu plans are excluded, and one setting covers personal accounts. Both providers' published policies are linked from our homepage.

On disconnect

Disconnecting a company revokes the token with Intuit and deletes it from our servers. Deleting your account erases the rest. These are also your rights under Quebec's Law 25.

What we don't have

No SOC 2 audit yet: we're a small team and we won't claim certifications we don't hold. The day we earn one, it will be listed here. To report a vulnerability or ask anything: support@caribooks.com, and we answer fast.

Full privacy policy