Security

Trust must be engineered.

961Finance is designed as production financial infrastructure: layered controls, explicit boundaries, measurable recovery, and no silent AI actions.

Tenant isolation

Every owned record includes an immutable business identifier. Deny-by-default Postgres policies are enforced below the API.

Identity assurance

Verified email, secure cookies, session revocation, and mandatory MFA for sensitive roles and actions.

Accounting integrity

Atomic balanced posting, decimal money, idempotency, locked periods, immutable entries, and traceable reversals.

Private data handling

Private storage, validated uploads, redacted logs, safe notifications, encrypted backups, and no financial data in URLs.

Audited operations

Role checks apply across finance, files, search, exports, messages, support, Realtime, and Arze tools.

AI controls

Permission-scoped retrieval, tool allowlists, strict schemas, confirmation gates, injection defenses, and spend limits.

Shared responsibility

We protect the platform and provide secure controls. Businesses remain responsible for authorized access, source-document accuracy, approvals, and professional accounting or legal review. 961Finance does not hold funds, submit taxes, calculate payroll, or provide investment, credit, legal, or tax advice.

Built by 961 Developments

961Finance is a 961 Developments company and follows a security-first product discipline. Learn more at 961 Developments.

Report a concern

Security reports can be sent to the address published in our security policy. Please do not include customer financial records in email.