Enki BookkeepBack to home

Data Security Policy

Last updated 19 June 2026

Enki Digital Pty Ltd ("Enki") treats the security of your financial information as fundamental to the Enki Bookkeep service (the "Service"). This policy describes the technical and organisational measures we use to protect data, and the responsibilities we share with you. It forms part of the Enki Bookkeep Agreement and should be read with the Terms of Service and Privacy Policy.


1. Our security posture and standards alignment

The Service is designed and built to align with the control principles of SOC 2 and ISO/IEC 27001, and with the Australian Privacy Principles, and is aligned with the Australian Cyber Security Centre's Essential Eight mitigation strategies. We are on a path toward formal certification and uplift our controls as we grow.

2. Hosting and data residency

2.1 The primary copy of your data is hosted in Sydney, Australia (Supabase, ap-southeast-2), and our application compute is configured to run in an Australian region (Vercel, syd1) where practicable.

2.2 Some processing necessarily occurs outside Australia — in particular, the AI model providers used to read documents and suggest coding may process content in the United States or other locations. We engage those providers under terms that prohibit training on your content and apply zero-data-retention or equivalent protections where reasonably practicable, and we minimise the personal information sent to them. See the Privacy Policy for cross-border details.

3. Encryption

3.1 Data is encrypted in transit using TLS, and at rest using the encryption provided by our hosting and storage infrastructure.

3.2 Secrets and credentials (such as API keys and integration tokens) are held in protected secret stores and, where stored in our database, are encrypted at the application layer. Secrets are never exposed to client-side code.

4. Access control and multi-tenant isolation

4.1 Tenant isolation. The Service is multi-tenant and enforces isolation at the database layer using row-level security, so that each customer's data is accessible only within that customer's organisation. Access is additionally scoped in the application layer.

4.2 Least privilege. Access to systems and data is granted on a need-to-know, least-privilege basis and reviewed periodically. Production access is restricted and logged.

4.3 Authentication. User access requires authentication; we support, and for privileged and accountant roles encourage or require, multi-factor authentication. Role-based permissions govern what each user can see and do, and your external accountant (where granted access) uses a separate, scoped login.

5. Human-in-the-loop and audit logging

5.1 The Service is designed so that automated and AI-generated outputs are suggestions requiring human review; nothing is finalised, recorded as final, or lodged without a person approving it.

5.2 We maintain audit logs of security-relevant and record-relevant events (such as sign-ins, access changes, document processing, approvals, exports, and deletions) to support accountability, investigation, and the integrity of your records.

6. AI and data handling

6.1 We design the extraction pipeline to be model-agnostic and route processing through a controlled gateway. We do not permit the AI providers we engage to train their models on your content, and we apply zero-data-retention or equivalent settings where reasonably practicable.

6.2 We minimise the personal information included in prompts to what is needed for the task, and we validate AI outputs in our own code (including recomputing monetary figures) rather than trusting model arithmetic.

6.3 We treat document content as untrusted input and design the pipeline so that instructions embedded in a document cannot cause the Service to take an action — extraction proposes; our code and your review dispose.

7. Application and infrastructure security

7.1 We follow secure-development practices, including code review, version control, and change management through reviewed pull requests, with changes deployed through an automated pipeline.

7.2 We apply protective measures at the edge (such as a web application firewall, bot filtering, and rate limiting), set appropriate security headers, and manage dependencies with lockfiles and automated vulnerability monitoring to reduce supply-chain risk.

7.3 Uploaded files are validated and handled in isolated processing steps, stored in private storage, and served only via short-lived, access-controlled links.

8. Backups and resilience

8.1 We maintain backups of the production database (including point-in-time recovery where available) to support recovery from data loss, and we periodically verify our ability to restore.

8.2 Backups are retained for a defined period and then deleted in the ordinary cycle, and are protected by the same access controls and encryption as production data.

9. Sub-processor and vendor management

We select reputable infrastructure and service providers (which are themselves subject to recognised security programmes), engage them under terms requiring appropriate security and confidentiality, and maintain a current list of sub-processors (available on request — see the Privacy Policy). We review providers when they are onboarded and as circumstances change.

10. Incident response and breach notification

10.1 We maintain an incident-response plan covering containment, assessment, notification, and review.

10.2 If we become aware of a data breach likely to result in serious harm to affected individuals, we will assess it and, where required by the Notifiable Data Breaches scheme, notify the affected individuals and the Office of the Australian Information Commissioner as soon as practicable, and we will notify affected customers in accordance with our agreement and the law.

11. Shared responsibility — your part

Security is a shared responsibility. You are responsible for: keeping your credentials secure and enabling multi-factor authentication; granting access only to authorised users and removing access promptly when it is no longer needed; ensuring you have the right to upload the data you provide and that it is lawful; reviewing and verifying outputs before relying on them; and maintaining your own independent records (including exports for taxation record-keeping). Configuration and access decisions within your account are your responsibility.

12. Responsible disclosure

We welcome good-faith reports of security vulnerabilities. Please contact hello@enkidigital.solutions with details and follow the responsible-disclosure terms in our Terms of Use. We will investigate promptly and will not pursue good-faith research that complies with those terms.

13. Limits and review

13.1 No system, control, or method of transmission or storage is completely secure. This policy describes the measures we take; it is not a warranty of absolute security, and it operates subject to the disclaimers and limitations in the Terms of Service.

13.2 We review and update this policy and our controls periodically and as our practices and the threat environment evolve.

14. Contact

Security enquiries and reports: hello@enkidigital.solutions. Privacy enquiries: see the Privacy Policy.


This document describes Enki's security practices for the Enki Bookkeep service. It is not tax, financial, or legal advice. © 2026 Enki Digital Pty Ltd.

Privacy PolicyTerms of ServiceTerms of UseData Security Policy

© 2026 Enki Digital Pty Ltd. This material is not tax, financial, or legal advice.