You are being asked to put client tax records and financial documents into someone else's software. This page describes the controls that exist in the product today, in enough detail that you can ask us to prove any one of them.
If a control is not on this page, assume we do not have it yet. We would rather lose the deal than describe something we cannot show you.
One region, named. No unexplained replicas and no per-tenant surprises.
Accute is served from the United States today. If your engagement letters or local regulator require data to stay in another jurisdiction, raise it before you sign rather than after. We will tell you plainly whether we can meet it.
The question behind every security review of a shared platform: can another firm ever see my clients?
Named algorithms and named key custody, so your reviewer has something to check.
Who can do what, how they prove who they are, and what stops a request that should not have been made.
A log is only useful if you can tell whether someone edited it. These are hash chained, so a deleted or altered row breaks the chain.
| Log | What it records | Tamper evidence |
|---|---|---|
| Application audit trail | Sign-in and sign-out, MFA changes, role and permission changes, document access and sharing, exports, API key issue and revoke | Hash chained: each entry stores a SHA-256 hash of itself and of the entry before it |
| Cryptographic operations | Encrypt, decrypt, wrap, unwrap, rotate, create and revoke, with the actor, IP address and user agent | Sequence numbered and hash chained with SHA-512, with optional signing for non-repudiation |
| Encryption events | Which action ran, against which resource, and whether it succeeded or failed | Indexed by timestamp, action and outcome for review |
| Credential access | Reads and writes against stored third-party credentials | Written on the same path as the operation, so a successful use cannot skip the log |
How a release reaches you, and what happens to data after it stops being used.
Accute runs on managed Cloud SQL for PostgreSQL, so backup and point-in-time recovery are configured at the instance rather than in the application.
We do not publish the schedule or the recovery targets on this page. Ask for the current configuration in writing during procurement and we will confirm it before you sign.
Removing an installed AI agent keeps its data for a restore window, 90 days by default, before it is cleared. The reason and the person who removed it are recorded.
Retention for your firm's records at the end of a contract is set in the agreement, not by a default in the product.
The third parties that can process firm data as part of running Accute.
| Provider | Purpose | Where |
|---|---|---|
| Google Cloud | Application hosting, PostgreSQL database, document storage, secret storage | us-central1, United States |
| Microsoft Azure Key Vault | Hardware-backed key encryption keys for envelope encryption | Configured per deployment |
| FinACEverse CAP | Identity gateway, subscription and billing. Operated by the same company as Accute | app.finaceverse.io |
| FinACEverse Command Center | Routes AI requests to the model provider configured for your firm | command.finaceverse.io |
| Model providers | OpenAI, Anthropic and Azure OpenAI, reached only through the router above | Provider regions |
| Resend | Transactional email such as notifications and invitations | Provider regions |
Connectors you switch on yourself, such as an accounting ledger or a mail provider, add their own processor to this list for your firm only. The full current list, including anything specific to your configuration, is available on request.
This page does not claim a certification for Accute. Plenty of vendors put an audit badge on a marketing page and hope nobody asks which entity and which scope it covers. We would rather you asked us directly.
Accute runs on Google Cloud and Microsoft Azure infrastructure that carries its own independent audits. Those are the providers' certifications, not ours, and inheriting infrastructure controls is not the same as being certified.
Our current certification and attestation status is available on request, under NDA, along with the underlying evidence. Write to security@accute.io and we will tell you exactly what is held and what is not.
If you have found a weakness in Accute, tell us before you tell anyone else and we will work it with you. Send the affected URL or endpoint, the steps to reproduce, and what an attacker could reach.
Please do not run automated scans against production, and do not access, modify or retain another firm's data while testing. A single proof of access is enough.