Skip to content

Security principles

Built around keeping your financial information private

These are the product principles guiding how BusinessHQ360 is designed and built. They describe our approach and planned capabilities, not third-party certifications.

  • Isolated workspace per business

    Every business's records are scoped to that business, never pooled together.

  • Role-based access

    Owners, admins, and team members each get only the access their role needs.

  • Controlled accountant permissions

    You decide what your accounting firm can view or request.

  • Protection of financial information

    Sensitive financial data is handled as a first-class design constraint.

  • Transparent activity history

    Meaningful actions are recorded so changes can be reviewed later.

Placeholder document

What these principles mean today

BusinessHQ360 is in active development. The statements below describe design commitments and planned capabilities rather than completed third-party audits or certifications.

Workspace isolation

Every business record is scoped to a business identifier, and access checks will be enforced in the database rather than only in the interface.

Access control

Owners, admins, members, and viewers will each receive a defined set of permissions, and accountant access will be granted per relationship.

Activity history

Meaningful actions will be recorded so you can review who changed what and when.

Certifications

We do not claim any specific security certification. Any certification will be published here once it is confirmed.