Security built for financial records
Your ledger, your payroll and your customer list are among the most sensitive things your business owns. DavoBooks treats them that way.
What protects your data day to day
These controls are part of the product itself, not optional add-ons that have to be switched on later.
Role-based access
Directors, accountants, store keepers and staff each see only the modules their role allows. Permissions are checked on the server, not just hidden in the interface.
Company data isolation
Records belong to a company and queries are scoped to it. One company's invoices, customers and payroll can never appear in another company's workspace.
Encrypted in transit
The application is served over HTTPS only, with strict transport security so browsers refuse to fall back to an insecure connection.
Complete audit trails
Creation, approval, editing and cancellation are recorded with the user and timestamp, so you can always reconstruct how a figure was produced.
Approval workflows
Expenses, purchases and invoice payments can be routed for approval instead of being posted by whoever happens to be at the keyboard.
Read-only AI assistant
The assistant answers questions from your company data and cannot create, edit or delete a single record.
Monitored infrastructure
Servers, certificates and application logs are monitored continuously so issues are found by us before they become your problem.
Backups and recovery
Scheduled backups are taken and recovery procedures are tested, because a backup you have never restored is not really a backup.
Who can see and change what
Permissions are enforced on the server. Hiding a menu item is a convenience - it is never the only thing standing between a user and a record.
| Role | Typical access |
|---|---|
| Director / owner | Company performance, approvals, staff and all financial records |
| Accountant | Invoices, expenses, bank accounts, reports and reconciliation |
| Store keeper | Stock items, quantities, transfers and receiving |
| Counter staff | Point of sale and customer receipts for their location |
| Customer portal user | Their own invoices, statements and shared documents only |
How we run the platform
Controls only help if the systems behind them stay healthy.
- Servers, certificates and application logs are monitored so problems are found by us first.
- Scheduled backups are taken and restores are tested, because an untested backup is not a backup.
- Application dependencies and framework security releases are tracked and applied.
- Staff access to production systems is limited to the people who need it, and is logged.
Reporting a security concern
If you believe you have found a vulnerability in DavoBooks, please report it privately rather than testing it against live customer data. Include enough detail for us to reproduce the issue and we will acknowledge it promptly.
Within scope
The DavoBooks web application, its authentication and its APIs.
Out of scope
Denial-of-service testing, social engineering of staff, and testing against accounts or data you do not own.
Contact the teamQuestions about your compliance requirements?
Tell us what your auditor or regulator needs to see and we will tell you plainly what the platform provides today.
