SECURITY & DATA HANDLING

Your books deserve careful access, clear boundaries, and less unnecessary exposure.

Bookkeeping requires trust. Our operating approach is to minimize unnecessary access, use client-controlled QuickBooks permissions, avoid password sharing, separate public intake from sensitive document exchange, and keep human review in the workflow when bookkeeping decisions require context.

Client-Controlled QBO No Password Sharing Minimal Public Intake Human Review
Client-controlled QBO Your business retains control of its accounting environment.
Scoped access Access should match the bookkeeping responsibilities being performed.
No credential sharing Master passwords and MFA codes should remain with the authorized user.
Claims match reality We do not advertise certifications or controls that are not verified.
Operating Principles

Good bookkeeping security starts by reducing what should never be exposed in the first place.

The objective is not to collect every possible credential or document. It is to obtain only the access and information necessary for the accepted bookkeeping scope.

01

Minimum Necessary Access

Bookkeeping access should be limited to what is needed for the agreed responsibilities rather than broad access by default.

02

Client-Controlled QBO

The business should retain control of its QuickBooks Online company and manage access as responsibilities change.

03

No Password Sharing

Personal master credentials, banking usernames/passwords, and MFA codes should not be the method used to provide bookkeeping access.

04

Separate Sensitive Exchange

Public lead forms are for qualification. Sensitive records should be exchanged only through the appropriate protected workflow when truly required.

05

Human Review

Automation can assist repetitive work, but uncertain classifications, exceptions, corrections, and historical questions should receive human review.

06

Clear Scope Boundaries

Bookkeeping, QuickBooks Setup, historical cleanup, tax matters, and other professional services should be separated rather than mixed into one undefined access request.

QuickBooks Access

The client should remain in control of the accounting environment.

The preferred workflow is for the client business to own its QuickBooks Online company and grant the appropriate authorized access for the accepted setup, cleanup, or monthly bookkeeping responsibilities.

Explore QuickBooks Setup
01
Business owns the QBO environment The bookkeeping system remains associated with the client business.
Client Control
02
Authorized user access Access is granted through the appropriate account or professional workflow.
Scoped
03
Individual accountability Each authorized person should use the credentials assigned to that individual rather than a shared master login.
Individual
04
Access can change Permissions can be adjusted when responsibilities or the relationship change.
Revocable
05
No banking credentials through intake forms Bank usernames, passwords, and MFA codes should never be submitted through general website forms.
Never
Do Not Send Through Public Forms

Some information should never be part of a preliminary bookkeeping inquiry.

An initial price check can be completed using workload and business-context information. Sensitive credentials and financial records are unnecessary at that stage.

PW
QuickBooks passwordsUse authorized access instead of sharing personal credentials.
Do not send
BK
Bank usernames or passwordsBank credentials are not required for public qualification.
Do not send
2FA
MFA / verification codesAuthentication codes should remain private to the authorized user.
Do not send
ID
SSNs, tax IDs, or identity credentialsThese are not needed for an initial bookkeeping price check.
Do not send
DOC
Statements and financial documentsDo not attach sensitive records to a general inquiry unless a protected workflow has specifically been provided.
Use proper channel
AI-Assisted Bookkeeping

Automation should reduce repetitive work without removing responsibility.

Technology can help organize information, identify patterns, surface possible duplicates, and prepare suggestions. A person remains responsible for reviewing exceptions and context-dependent bookkeeping decisions.

Technology can assist

01Transaction organization and pattern recognition
02Possible duplicate detection
03Possible categorization suggestions
04Exception and anomaly flagging
05Workflow and document organization support

Human review remains important

01Uncertain or unusual transactions
02Client-specific business context
03Historical corrections
04Reconciliation differences
05Final approval of supported bookkeeping actions
If the system is uncertain, the answer should become a question—not a guess.
Documents & Retention

Collect only what the bookkeeping work requires.

The document workflow should minimize unnecessary copies, use the accounting system when practical, while avoiding unnecessary duplicate copies and unnecessary retention.

01

Prefer Existing QBO Records

When appropriate, use documents and transaction support already associated with the accounting environment rather than creating unnecessary duplicate copies.

02

Use Secure Exchange When Needed

Documents that QBO does not hold should move through the protected workflow designated for the engagement rather than a public lead form.

03

Limit Retained Data

Records should be retained only as needed for the bookkeeping engagement, operational requirements, or applicable obligations; unnecessary temporary working copies should be minimized.

04

Separate Client Data

Each client's records and workflow should remain logically separated from other client work, with access based on the responsibilities assigned.

Security claims should match reality.

We do not intend to market certifications, audit results, security standards, encryption claims, or compliance frameworks that have not actually been implemented and verified. As systems and procedures change, this page may be updated so its descriptions remain accurate. No website or online system can eliminate all security risk.

Questions about this page? admin@cifracove.com
Security Questions

Practical answers about access and information handling.

No. The preferred model is authorized access through the appropriate QuickBooks workflow rather than sending personal master credentials.

No. Banking usernames, passwords, and MFA codes should not be provided through general forms, email, or routine bookkeeping communication.

Only basic business and workload information such as QuickBooks status, transaction range, number of financial accounts, book condition, and general contact information. Sensitive financial records are not needed for the initial estimate.

The operating model is AI-assisted rather than blindly autonomous. Technology may surface suggestions and exceptions, while supported bookkeeping actions requiring judgment remain subject to human review.

No certification should be inferred unless it is specifically stated and independently verifiable. This page intentionally avoids claiming security certifications that are not actually in place.

No. Online systems always involve some level of risk. The goal is to reduce unnecessary exposure, use appropriate controls, limit access, and keep security practices aligned with the actual production environment.

Start the bookkeeping conversation without handing over sensitive credentials.

Use the price-check process to describe the workload first. Access and document exchange come later, only when the engagement and bookkeeping scope require them.

Check My Price →
Scroll to Top