Islandbridge Automation Limited
Product: Accruate

Security Statement

Last updated: August 7, 2026

At Islandbridge Automation Limited, we understand that as an accounting platform, the security of your financial data is paramount. We are an early-stage company committed to building a secure foundation from day one. This statement outlines the technical and organizational measures we take to protect your data.

Data Encryption

  • Encryption at Rest: All user data and uploaded documents are encrypted at rest using industry-standard AES-256 encryption via our database provider, Supabase.
  • Encryption in Transit: All data transmitted between your browser and our servers is encrypted using Transport Layer Security (TLS/SSL).

Infrastructure & Hosting

  • Cloud Providers: Our infrastructure is hosted on Vercel and Supabase. Both are industry leaders in reliability and security.
  • Data Residency: We prioritize EU data residency. Our database and file storage are hosted in AWS regions located in the European Union (Ireland/Germany). Our error monitoring runs in Sentry's European region.

Access Control

  • Authentication: We use secure, token-based authentication. Passwords are stored only as salted hashes by our authentication provider, and are never visible to us.
  • Multi-Factor Authentication: Every account can enable a second authentication factor, using either an authenticator app or a one-time code sent by email. Once a factor is enrolled, it is enforced on every request to our application interface, not only at login.
  • Tenant Isolation: Access to each client workspace is enforced at the database level through row-level security, so one customer's data cannot be reached from another customer's session. Every request is independently checked against the caller's membership of that workspace.
  • Internal Access: Access to customer data by Islandbridge Automation personnel is strictly limited to authorized individuals who require it for support or engineering purposes.

Third-Party Integrations (Xero)

We integrate with Xero using OAuth 2.0 — we never see or store your Xero username or password. Xero API tokens are stored in Supabase Vault, encrypted at rest, and can only be accessed by secure backend functions when required for syncing.

AI Data Processing

Document extraction and email-based document chasing are powered by the Google Gemini API. We use Google's paid API services, which means your financial documents, related email messages, and extracted data are not used to train Google's publicly available AI models.

Data Integrity & Backups

Our database is backed up daily, with backups retained for seven days, so that your data can be recovered in the event of a system failure.

Please note that Accruate is not a backup or archival service. You remain responsible for retaining original copies of your invoices, receipts, and financial records for as long as your own tax authority requires.

No Sale of Data

Our business model is based on subscriptions, not selling user data. We do not sell your personal or financial data to advertisers or third parties, and we run no advertising or tracking technology.

Reporting Issues

If you believe you have found a security vulnerability in Accruate, please report it to us at haksing@islandbridge.io.

We will acknowledge your report within three business days. We ask that you give us a reasonable opportunity to investigate and fix the issue before disclosing it publicly, and that you do not access, modify, or delete data belonging to anyone else while investigating. We will not pursue action against researchers who report issues in good faith and follow these guidelines.