Financial workflows need visible controls, not vague assurances.
Arveo handles operational and accounting context for firms. This page separates controls that are live from assurance work in progress and capabilities still planned.
What is operating today.
Status labels describe the product and assurance program as they exist now. Planned items are not represented as available.
Encryption
- TLS for data in transit
- Managed encryption at rest
- OAuth tokens encrypted separately
Access control
- Firm and client role boundaries
- Database row-level policies
- MFA step-up for firm administrators
Audit history
- Sensitive actions recorded
- Accounting approvals traceable
- Connection events retained
Authentication
- Managed identity provider
- Authenticator or email verification options
- Server-validated roles
Assurance program
- SOC 2 readiness program
- Control evidence collection
- Vendor and incident procedures
Enterprise access
- SAML single sign-on
- Expanded security exports
- Customer-specific access policies
The accounting file stays in QuickBooks.
Arveo operates around the system of record and stores the context required to manage work, review decisions, and communicate with the client.
QuickBooks Online
The accounting file remains the system of record. Access uses the official OAuth and accounting APIs.
Arveo
Arveo stores the workflow context needed to operate the product, separated by firm and client access boundaries.
AI processing
Only the context required for the task is sent to configured AI providers. Credentials and tenant identifiers are excluded.
Access is scoped at both the firm and client level.
The authorization model combines server-validated roles with database policies. Firm users receive only the client access their role allows, while client users enter a separate client-facing experience.
Firm boundary
Firm A cannot query or operate Firm B records.
Client boundary
Client workspaces and learned context remain scoped to the client.
Role boundary
Firm administrators, staff, and clients receive different access paths.
Enterprise SSO
SAML-based identity and organization policy controls.
Bring your security questionnaire to the demo.
We will answer against the controls that exist today, identify documentation available during diligence, and separate roadmap items from live capabilities.