Skip to content
Trust & Security

SOC 2 is coming. Here's what's already true.

You’re trusting us with read access to your books before we can hand you a SOC 2 report. So instead of asking you to take our word for it, this page names the provider, the encryption, the backups, and the controls. No “bank-level security” standing in for specifics.

Read-only access

No payment rail

Period locks

Full audit trail

Read-only, by design

We connect the same way your accountant already does. We can see transactions, statements and documents. We cannot move money, ever — there is no payment rail wired into cruisr, not a disabled one, one that isn’t built.

Permissioned and logged

Segregation of duties, dollar-threshold approvals, period locks and an evidence trail on every entry. These are product features, not just internal practice.

Law 25, and revocable

We handle financial and personal data in line with Quebec’s Law 25. You can revoke our access from your own QuickBooks or Xero admin panel at any time, no call required.

  • Read-only access, always
  • Segregation of duties enforced
  • Dollar-threshold approvals
  • Period locks
  • Full audit trail
  • Law 25 (Quebec) compliant
  • SOC 2 Type II in progress, targeting Q4 2026
Encryption, hosting and residency

How your data is protected, and where it lives

The specifics, named. Every value in the grid is marked “example” — these are placeholders showing the shape of the answer, not confirmed values, and each one has to be replaced with the real specific before this page goes live.

Access control

[named roles/group], least-privilege, logged, reviewed [cadence], and revoked on offboarding.

Restore drills

Backups are only worth what a restore proves. Drills tested [cadence].

Revocable by you

Access is revoked from your own QuickBooks or Xero admin panel, without contacting us.

No move-money permission

Not requested, not held, and not built. There is no payment rail in the product.

In transit

example

TLS 1.3

At rest

example

AES-256

Hosted on

example

AWS

Data residency

example

Canada (ca-central-1)

Backup cadence

example

Every 24 hours

Backup retention

example

30 days

The control fabric

What stops AI-kept books from being a leap of faith

Every control a controller would insist on, applied to work the AI prepared.

Segregation of duties

Work moves prepare → review → approve, and the same person can never hold two of those steps on the same item.

Dollar-threshold approvals

Dollar thresholds decide what needs an owner rather than a controller. Rights are set per financial area, not per person by hand.

Period locks

When you approve the close, the period locks. Reopening one takes an approval and leaves a record, so a closed month cannot quietly change under you.

Full audit trail

Every entry carries its source document, who prepared it, what changed and who approved it. Audit evidence is a by-product of the month, not a project after it.

Depending on who you are

Common questions, answered directly

  • I’m a bookkeeper considering cruisr for a client

    You are not handing over the relationship, and you are not signing up for someone else’s mistakes. cruisr works inside the client’s own QuickBooks or Xero, under their admin — you keep your access, and you can see every entry cruisr posts along with the document and the approval behind it. Nothing posts above a threshold without a named human approving it, so there is no unattributable work landing in a file with your name on it.

  • I’m a business owner and I’ve never done this before

    The honest answer to “what if the AI gets it wrong” is that it does, sometimes — which is why it is not the last step. Every entry carries a confidence level, and low-confidence items are never posted silently: they go to a person. On a typical night that is 9 of 1,820 transactions. You approve the close before the period locks, and if something is wrong afterwards, the audit trail shows what changed and who changed it.

  • I’m a controller or CFO evaluating this for the group

    The mechanics you will want to test are the ones named on this page: read-only connections, segregation of duties, dollar-threshold approvals, period locks, and drill-down from a consolidated line to the source document behind it. If you want to put them against a real close rather than read about them, bring us your last one.

    Talk to us about your close →

Disclosure

Security incidents, disclosed

We have no security incidents to report. If that changes, this page will say so — with what happened, what we did, and when — not a quiet fix.

Quebec

Law 25 and Quebec compliance

  • Named privacy officer — [name/title]
  • Data collected and used only for the purposes we disclose
  • Safeguards proportional to the sensitivity of the data
  • Breach notification to affected individuals and to the CAI
  • Right to access, correct, and delete your personal information

The full detail is in the privacy policy.

Questions we get from security reviews

With most books, no — the error surfaces when someone finally reconciles or when a lender asks. cruisr reconciles every bank and card account continuously, so a mismatch surfaces the day it happens rather than at year-end, and every entry carries the document and the approval behind it. The audit trail is what makes the answer to that question "yes".

See exactly what we'd have access to. Before you connect anything.

The free diagnostic runs on your own QuickBooks or Xero, read-only, and you get the readout whether or not you buy.