Security

Your data sits in the EU and stays yours.

A set of books contains your revenue, your customers and your margins. That is why Readybooks is built on the assumption that something will go wrong one day, and why the most important locks are not in the application but in the database beneath it.

Someone works on a laptop by a window overlooking the city.
Stored in the EUYour administration and your backups sit inside the European Union
Separated per administrationRow-level isolation, enforced by PostgreSQL
ImmutableJournal lines are never changed or deleted

Where your data lives.

The application, the database and the backups run inside the European Union. Traffic goes over HTTPS only, and data is encrypted at rest. Which processors we use and where they sit, we keep in a public list you can read before you create an account.

Isolation that does not depend on paying attention.

Every administration-bound table carries its own administration id, and PostgreSQL enforces with row level security that a session can only reach the administration it was opened for. If the application made a mistake, there is still a second lock that stays shut.

  • Row level security, mandatory on every table
  • A runtime role without the right to bypass those rules
  • Isolation proven with tests against the real database
  • No query without an explicit administration
A tidy workspace with a monitor and plants.

What happened, stays.

Journal lines cannot be changed or deleted, not even by us: the runtime role simply does not have those rights. A correction is a reversal. Every meaningful action lands in an audit log with user and timestamp, and a closed period locks.

Signing in without a password.

Readybooks uses passkeys. There is no password to leak, guess or reuse, and phishing does not work because the key is bound to the domain. For sensitive actions we ask for the passkey again, even when you are already signed in.

Your data stays yours.

You can export your whole administration at any time in JSON and XAF, including after you cancel. If you cancel, your administration moves to read-only mode free of charge so you can meet your legal retention obligation. Earlier deletion we carry out within thirty days of you confirming you have an export.

  • Export in JSON and XAF, always
  • Read-only mode free of charge after cancelling
  • Deletion on request within thirty days
  • No use of your data for anything else
A business owner sits calmly in a bright room.

Frequently asked questions

Do you sell my data or train models on it?

No. Your administration is used to make Readybooks work for you and for nothing else. What we do and do not do is set out in the privacy statement and in the data processing agreement.

Who inside Readybooks can reach my administration?

Staff access is limited to what support requires and is logged. The application's runtime role cannot change or delete journal lines, and that holds during maintenance too.

What happens in a data breach?

We have a fixed procedure with fixed deadlines: investigate, contain, notify the supervisory authority within seventy-two hours where required, and inform those affected if the risk calls for it.

Can I get a data processing agreement?

It already exists and applies to everyone; you do not have to ask for it and nothing needs signing. You will find it alongside the list of sub-processors with the legal documents.

Read first, create an account after.

The privacy statement, the data processing agreement and the list of sub-processors are public, before you fill anything in.

Free
1 user, 2 finalized invoices per month
Paid
from €4.99 per month per administration
Your accountant
free, and never counts towards your limit
Cancelling
monthly, and your export stays available

Every feature is in every paid plan. All you choose is how many people need access.