Security and trust

Financial workflows need visible controls, not vague assurances.

Arveo handles operational and accounting context for firms. This page separates controls that are live from assurance work in progress and capabilities still planned.

Tenant isolation controls live
SOC 2 program in progress
Control status

What is operating today.

Status labels describe the product and assurance program as they exist now. Planned items are not represented as available.

Live

Encryption

  • TLS for data in transit
  • Managed encryption at rest
  • OAuth tokens encrypted separately
Live

Access control

  • Firm and client role boundaries
  • Database row-level policies
  • MFA step-up for firm administrators
Live

Audit history

  • Sensitive actions recorded
  • Accounting approvals traceable
  • Connection events retained
Live

Authentication

  • Managed identity provider
  • Authenticator or email verification options
  • Server-validated roles
In progress

Assurance program

  • SOC 2 readiness program
  • Control evidence collection
  • Vendor and incident procedures
Planned

Enterprise access

  • SAML single sign-on
  • Expanded security exports
  • Customer-specific access policies
Data flow

The accounting file stays in QuickBooks.

Arveo operates around the system of record and stores the context required to manage work, review decisions, and communicate with the client.

01

QuickBooks Online

The accounting file remains the system of record. Access uses the official OAuth and accounting APIs.

02

Arveo

Arveo stores the workflow context needed to operate the product, separated by firm and client access boundaries.

03

AI processing

Only the context required for the task is sent to configured AI providers. Credentials and tenant identifiers are excluded.

Tenant isolation

Access is scoped at both the firm and client level.

The authorization model combines server-validated roles with database policies. Firm users receive only the client access their role allows, while client users enter a separate client-facing experience.

Review active sub-processors

Firm boundary

Firm A cannot query or operate Firm B records.

Live

Client boundary

Client workspaces and learned context remain scoped to the client.

Live

Role boundary

Firm administrators, staff, and clients receive different access paths.

Live

Enterprise SSO

SAML-based identity and organization policy controls.

Planned
See it with your workflow

Bring your security questionnaire to the demo.

We will answer against the controls that exist today, identify documentation available during diligence, and separate roadmap items from live capabilities.

Book a demo