Skip to content

Security and privacy

Every record in OneBooks belongs to exactly one business and every request is checked against the business you are signed into. Users, connected apps and AI agents can only reach the business they were granted access to.

  • Email and password (verified email required) or Google sign-in.
  • Sessions expire; Keep me signed in extends them on trusted devices. Sign-in is rate-limited against guessing.
  • Password resets are sent only to the account’s verified address.

Owner, Admin, Member and Viewer, plus per-user grants and revokes. The same permission set gates the app, the API, the AI assistant and connected apps. See Users, roles and permissions.

Posted journal lines are never edited or deleted — corrections are new reversing entries, and every document keeps its number after voiding. Locked fiscal years block changes to closed periods.

Third-party apps connect over OAuth 2.0 with the scopes you approve and can be revoked at any time. POS tokens are stored encrypted. Webhooks from POS providers are signature-verified.

Tool results and uploaded documents are treated as data, not instructions; every write requires a human confirmation; no destructive actions are exposed to AI. See Safety, privacy and limits.

Signing keys for ZATCA devices are generated server-side and stored encrypted; production secrets are protected with a dedicated key. Invoice hashes chain each document to the previous one, as ZATCA requires.

You can export everything at any time. Deleting a conversation removes only the chat; documents stay. For data requests or deletion of an account, contact support — see Get support.

Was this page helpful?No, tell us why