Security & trust
Your data, protected.
dexIQ handles finance data for bookkeeping firms and businesses, so security and auditability come first. Here is how we protect your data, what the AI can and cannot do, and the standards we hold ourselves to. In plain language.
The essentials
Built to be trusted with the books.
Your data is never used to train AI
Enterprise AI providers are contractually barred from training on your inputs or outputs. Nothing is retained by the model.
A human approves every action
The AI prepares and recommends. It never takes an irreversible action, like releasing a payment or changing bank details, on its own.
Encrypted in transit and at rest
HTTPS with TLS 1.2 minimum (1.3 where supported), and encryption at rest across the database, documents and backups.
OAuth, so no passwords stored
You connect via secure OAuth. dexIQ never sees or stores your passwords, only scoped tokens for the connection you authorise.
Your data lives in Australia
Stored in an Australian data centre, with disaster recovery in Melbourne. It stays onshore.
We store only what we need
Your mail inbox and accounting system stay your systems of record. dexIQ reads from them and keeps only what a task requires.
Least-privilege access, fully logged
MFA is mandatory, access is role-based and least-privilege, and every action is written to an audit trail.
Each customer is isolated
Multi-tenant isolation is a first-class control. Every record is scoped to your organisation and enforced on every request.
Guardrails against AI misuse
Inbound content is treated as untrusted data, not instructions, and approval is enforced outside the model.
Human-approved by design
The AI proposes. A human disposes.
The model is allowed to prepare, validate, recommend and explain. It is not allowed to execute anything irreversible. Your delegated authority is preserved, not replaced, and every material action is explainable and reviewable before it happens.
A deterministic layer of checks runs before the AI, and a policy and human-approval layer runs after it, so the AI never has the final word.
dexIQ never...
- Never releases a payment on its own.
- Never changes a supplier’s bank details without human verification.
- Never approves an invoice above your threshold without sign-off.
- Never overrides an existing control or approval workflow.
- Never sends an external message of financial weight without a human.
Security questions, answered
The questions your risk team asks.
Is dexIQ secure, and how do you protect our data?
Security is built into how dexIQ works, not bolted on. Your data is encrypted in transit and at rest, access is tightly controlled and logged, we connect through secure OAuth rather than holding your passwords, each customer is fully isolated, and a human approves every action the AI takes. dexIQ was built by a finance practice, for finance teams, so controls and auditability come first. We are happy to share our control mapping and answer your risk team's questions in detail.
Do you use our data to train AI models?
No. Your data is never used to train, fine-tune or develop AI models. We use enterprise API tiers from our AI providers, where the provider is contractually barred from training on our inputs or outputs. AI is used only at the moment of processing, to read and extract data from a document, and nothing is retained by the model afterwards.
Do you store our passwords or login credentials?
No. You connect your accounting system and inbox through secure OAuth, so dexIQ never sees or stores your passwords. We hold only scoped access tokens for the connection you authorise, kept in a managed secret store, encrypted at rest and access-controlled. No third-party provider is ever given your credentials, and you can disconnect at any time.
Is our data encrypted?
Yes. All traffic to and from dexIQ is served over HTTPS, with TLS 1.2 as the enforced minimum and TLS 1.3 used wherever your browser supports it. Data at rest is encrypted: the database, the invoice documents and attachments in object storage, and the backups. Staff devices are full-disk encrypted.
Where is our data stored?
Your data lives in an Australian data centre, with disaster recovery in Melbourne. We store only what we need to process your work: your mail inbox and your accounting system stay your systems of record, and dexIQ reads from them rather than replacing them. When the AI reads a document, that text may be processed by an AI provider for the moment of extraction only. It is transient, and nothing is stored offshore.
What data is actually sent to the AI?
Only the minimum needed for the task. Invoice text, supplier name and line items are sent so the AI can read them. Payroll, employee personal information and bank credentials are not. The smaller the data footprint to the model, the smaller the surface area for anything to go wrong. Every AI call is stateless and scoped to a single customer, with no shared context between customers.
Can the AI do something irreversible on its own?
No. The AI is allowed to prepare, validate, recommend and explain, never to execute an irreversible action. dexIQ never releases a payment on its own, never changes a supplier's bank details without human verification, never approves above your threshold without sign-off, never overrides an existing control or approval chain, and never sends an external message of financial weight without a human. A human confirmation costs seconds; an unwanted payment can cost weeks.
How do you handle privacy and personal information (PII)?
Through data minimisation and clear boundaries. We send the AI only what a task needs, and keep payroll and personal data out of it. Our handling is aligned with the Australian Privacy Principles under the Privacy Act 1988. We do not store card data: subscription billing runs through Stripe, which is PCI DSS Level 1 certified.
Who can access our data?
Access is least-privilege and logged. You sign in through Microsoft, Google or Xero and inherit the multi-factor authentication those providers enforce; internally, MFA is mandatory and shared logins are prohibited. Only the engineers required to support the service can reach production, under role-based access control. Every action on invoices, approvals and connections is written to an audit log with the user, the action, the outcome and a timestamp. Secrets and tokens are never written to logs.
Are you SOC 2 or ISO certified?
dexIQ is in active SOC 2 Type II readiness with Vanta; we do not claim certifications we do not hold. Our controls are designed against the recognised standards your auditors will know: ISO/IEC 27001 and ISO/IEC 42001, the NIST AI Risk Management Framework, the OWASP Top 10 for LLM Applications, APRA CPS 230 and the Australian Privacy Principles. We are glad to share our control mapping and sub-processor register with your audit or risk team on request.
What about prompt injection and other AI-specific risks?
We design against them directly. All inbound content, including invoices and emails, is treated as untrusted data, never as instructions, and approval rules are enforced outside the model, so even a successful prompt injection cannot release a payment because the model is not what releases payments. Hallucination is caught by deterministic checks against authoritative sources such as the ABN register and GST arithmetic, plus human approval. The model has no autonomy over money, master data or controls: it recommends, and your finance team approves.
How do you handle backups and disaster recovery?
Backups are automated and encrypted, and disaster recovery is designed to stay within Australia (Melbourne). Formal recovery-time and recovery-point targets are being finalised and will be published as part of our SOC 2 documentation. We would rather commit to numbers we can evidence than publish ones we cannot.
What happens if there is a security incident?
We maintain a data breach response plan aligned to the OAIC Notifiable Data Breaches scheme, covering assessment, containment and notification. If an incident affected your data, we would notify you promptly on becoming aware of it. A formal, exercised incident-response runbook is part of our current SOC 2 workstream.
Standards & frameworks
Designed against what your auditors know.
We hold ourselves to recognised standards, and we are careful about the difference between designed against and certified. dexIQ is in active SOC 2 readiness; the rest are frameworks our controls are designed against, not certifications we claim to hold.
Our control mapping and sub-processor register are available to your audit or risk team on request. Ask us for the security pack.