Security
How Mastro protects your clients' books
For a firm's vendor review under the FTC Safeguards Rule and IRS Publication 4557. Everything here describes what the system does today, and changes when the system does.
The data
What Mastro holds, and where
- Your clients' booksThe chart of accounts, journal entries, bank and card transactions, rules, reconciliations, and reports.
- What's shared in the portalDocuments, messages, and answers to your questions.
- ConnectionsAccess tokens for the banks a client connects through Plaid and the QuickBooks companies you move from, encrypted.
- PeopleNames, email addresses, roles, and sign-in records.
Never held: bank usernames or passwords (they go to Plaid, in Plaid's own window), card numbers, or anyone's Social Security number. Where: one server at Hetzner Online in Hillsboro, Oregon, with encrypted backups in a separate Hetzner Storage Box. All data stays in the United States.
Protection
Encryption, access, and sign-in
- In transitHTTPS only, with HSTS for two years and a strict Content-Security-Policy.
- At restBank and QuickBooks access tokens and every uploaded document are encrypted with AES-256-GCM. The key lives only on the server.
- One firm never sees another'sPostgres row-level security checks every query, and automated tests try to read across firms on every change.
- Inside a firmOwners, admins, and staff. Removing someone ends their access at once.
- ClientsSee only their own company, and only the months you've closed.
- Mastro's own staffSee firm-level details, never a client's amounts, transactions, documents, or messages.
- No passwordsA one-time code by email, valid for 10 minutes, with limits on codes and tries.
- Authenticator required for firmsFirm staff must also use an authenticator app, with recovery codes. Clients can turn it on.
The books
How the books stay right
- Every entry balancesAnd stays in its company. The database enforces it, not only the app.
- History can't be rewrittenThe ledger is append-only: a correction is a reversing entry, never an edit.
- People approve, rules suggestCategorization is done by rules a person writes or approves. No AI posts anything, and client data is never sent to an AI service.
- An activity logWho posted, changed, reversed, or closed what, and when.
Operations
Backups, monitoring, and changes
- Backups every hourEncrypted on the server before they leave it, and kept 48 hours hourly, 30 days daily, 12 weeks weekly, and 24 months monthly.
- A restore check every weekRun automatically. At most an hour of work can be lost.
- Watched every two hoursServices, the database, backups, the restore check, and disk. A failed backup emails the founder.
- No hands on the serverChanges ship only through pull requests that pass the full test suite, and a release that doesn't come up healthy rolls itself back.
Vendors
Who else touches client data
| Vendor | What for | What it sees |
|---|---|---|
| Hetzner Online | The server and backups | Encrypted backups; the server's disks |
| Plaid Inc. | Bank and card connections | What the client authorizes at their bank |
| Intuit Inc. | Moving from QuickBooks Online | The QuickBooks company you connect, read-only |
| Resend | Sending email | Recipient addresses and message text |
GitHub holds the code and runs the tests, with no client data. Cloudflare provides DNS only and never carries the app's traffic.
If something goes wrong
You hear within 72 hours
If Mastro confirms that someone got unauthorized access to a firm's data, it tells that firm within 72 hours: what was involved and when, what was done about it, and what the firm needs for its own notices.
Not in place yet: Mastro doesn't have a SOC 2 report or a third-party penetration test. This page will say so when either is done. Questions for your review: support@mastroledger.com.