Trust Center
Live security posture, automated audit results, and downloadable policies — updated daily. We believe security posture should be visible to prospects, not hidden behind a sales call.
Current Security Grade
A
90 / 100 composite score
Last daily audit
8/23/2026
Last weekly audit
8/23/2026
Score is computed in real time from automated audits running against our production stack. Findings are weighted by severity (Critical −25, High −15, Medium −6, Low −2) — and a 60/40 split blends daily + weekly results.
Where we stand across the frameworks that matter for SaaS bookkeeping.
Controls implemented; observation window in progress
DPA available; EU subprocessors listed
2026 rules implemented (fraud monitoring, return rate tracking)
Card data never touches MyBookie servers — Stripe-hosted checkout
Every control below is wired into production code — not a roadmap promise.
Bank-level encryption
TLS 1.3 in transit · AES-256 at rest
Authentication
Bcrypt password hashing · 2FA · JWT with DB-backed session revocation
Brute-force protection
IP + email rate limiting · automatic account lockouts · real-IP via X-Forwarded-For
Audit logging
Every login, password change, and sensitive action logged with IP and timestamp
Continuous security audit
Daily + weekly automated checks (database health, audit log, access controls, vendor exposure)
Real-time alerts
Critical/high findings emailed to admin within minutes via Resend
Bank data isolation
Plaid Production tokens encrypted; no raw bank credentials ever stored
Backups & continuity
MongoDB Atlas automated backups · documented Business Continuity Plan
Public documents are below. For SOC 2 control mappings or a signed DPA, email security@mybookie.ai.
How we collect, use, and protect your data.
ReadService agreement and acceptable use.
ReadVendors that process your data on our behalf.
View listWe turn these around in 24 hours for paid plans.
We take security reports seriously. Email security@mybookie.ai with details. We respond within 24 hours and credit responsible disclosure in our changelog.