Security Center
How we protect your financial data
AZ Finance takes the security of your financial data seriously. We employ multiple layers of protection to ensure your information remains safe, confidential, and available only to authorized users.
All data transmitted between your browser and our servers is encrypted using HTTPS/TLS. QuickBooks OAuth tokens are encrypted at rest using AES-256-GCM encryption. Passwords are hashed using bcrypt and are never stored in plain text.
Each client dashboard is protected by individual user accounts with email-based invitations. Two-factor authentication (2FA) is available via authenticator apps (Google Authenticator, Authy) or email verification codes. Admin access requires both a password and authenticator-based 2FA. Sessions are secured with HTTP-only cookies and expire after 30 minutes of inactivity.
We connect to QuickBooks Online exclusively through Intuit's official OAuth 2.0 protocol. We never see or store your QuickBooks username or password. We only request read-only access to the minimum data needed for financial reporting. You can revoke our access at any time through your Intuit account.
Our application is protected by Content Security Policy (CSP) headers that prevent cross-site scripting and other injection attacks. API rate limiting prevents abuse and brute-force attacks. All admin actions are recorded in an audit log for accountability. Each client's data is fully isolated — there is no cross-client data access.
Financial data is retrieved in real time from QuickBooks and cached temporarily (up to 4 hours) to improve performance. Cached data is automatically purged after expiration. We do not sell, share, or provide your data to any third parties.
If you discover a security vulnerability or have concerns about the security of your account, please contact us immediately at arman@armanzand.com.