Matchbook

Security & data residency

Books are private. We build like it.

You're trusting Matchbook with your clients' financial lives. Here is, plainly, how that trust is handled.

01Data stays in Canada

Documents, books, and client records are stored and processed in Google Cloud's Montréal region. Residency isn't a checkbox for us — it's where the infrastructure physically is.

02Encrypted everywhere

TLS in transit, encryption at rest, and dedicated encryption keys per credential type — a QuickBooks token is never protected by the same key as anything else.

03Two-factor on every account

Two-factor authentication is required on every password sign-in; accounts using Google single sign-on are authenticated through Google's own security controls. Role-based access keeps team members inside their lane, and client data scoped to the clients they serve.

04AI that doesn't keep your data

Document classification runs on enterprise AI APIs that do not train on your data. Identical documents are processed once and cached — your content isn't re-sent around the internet for fun.

05Humans approve, always

Nothing posts to a client's books without explicit approval from your team. Every posted entry keeps a link to its source document — a real audit trail, not a black box.

06Privacy law, taken seriously

Built to operate under PIPEDA and Québec's Law 25. Transactional email (verification, password resets, notifications) is delivered through a specialized email provider under a data-processing agreement; your documents and books themselves never leave the Montréal region.

Questions? Ask a human.

Security reviews, data processing agreements, or just a pointed question — write to hello@matchbookaccounting.ca and you'll get an answer from someone who can actually see the architecture.