Security & trust
Specifics, not badges.
Financial records are the last place for vague reassurance. Here is what Varetiq does structurally to protect your books — and what we are not claiming.
A person who prepares an entry cannot also approve it under the default configuration.
- Every permission
- Role-based
- Audit log
- Append-only
- Period reopenings
- Recorded
- Professional access
- Client-held
By module, action, and entity.
Entries cannot be edited or removed.
With a reason and a person.
Granted and revoked by you.
Design position
The strongest control is a system that cannot quietly change your books
Varetiq will suggest, flag, rank, and draft. It will not post to your general ledger on its own. Every ledger change is attributable to a person, carries a timestamp, and remains visible after the fact — including changes made by an outside accountant.
That is a deliberate constraint on the software rather than a setting you have to find and enable.
Structural controls
- Separate credentials for every person — no shared logins
- Preparer and approver separation on entries and bills
- Approval thresholds by amount, vendor, or account
- Closed periods locked; reopening requires a role and a reason
- Scoped, expiring access for outside professionals and lenders
- Document sharing that never exposes the ledger
- Complete, exportable audit log of every change
Your data
What we do with your records, stated plainly
It is yours
Full export of ledger, documents, and audit log at any time, in standard formats, at no charge — including if you leave.
It is not for sale
We do not sell customer financial data, and we do not share identifiable financial records with third parties for marketing.
It is minimised
We collect what the accounting requires. Where a capability needs more, we ask for it explicitly rather than assuming consent.
Limits
What we are not claiming
A security page that lists only strengths is not a security page.
- No certification, audit outcome, or compliance framework is claimed on this page
- No representation is made about suitability for any specific regulatory obligation
- Controls described here are product capabilities, not a guarantee against loss
- Nothing here is legal, tax, or accounting advice for your organization
Where a certification, attestation, or regulatory determination is completed in future, it will be published here with its scope, date, and issuing body — not implied by a logo.
Ask us something specific
If your organization has a security questionnaire, a lender requirement, or an auditor with questions, send them over and we will answer directly.