Security
Secured like a bank. Controlled by you.
Incremenza connects to your most important business data. We take that responsibility seriously. This is what we do, and what we do not do, with your information.
Layers of protection
Read-only by default
Most integrations (Stripe, Square, PayPal, Plaid, bank connections) are read-only. Incremenza cannot move money or modify your records on those platforms. We can only see them. QuickBooks has an opt-in write-back feature for transaction reconciliation, which you can disable.
Encryption everywhere
All data in transit uses TLS 1.2 or above. The production database is encrypted at rest on a managed cluster, and integration tokens are additionally encrypted with AES-256 before being stored. Database access is restricted to application servers over a private network and is not exposed to the internet.
OAuth 2.0 for all integrations
Incremenza never sees your passwords. Every integration uses OAuth 2.0, and you authenticate directly with the provider (Stripe, QuickBooks, your bank, etc.) and grant Incremenza specific permissions. You can revoke access at any time from your provider's settings.
You control your data
Admins can export all company data (transactions, customers, invoices, OKRs, team members) as CSV files at any time from Settings. You can disconnect integrations without losing historical data. You can delete your account, after which all personal and financial data is permanently deleted within 90 days.
Every account requires MFA
Multi-factor authentication is mandatory for every user. Administrators and managers must use a passkey, which is phishing-resistant. All other users choose between a passkey and an authenticator app.
Your data never crosses into another company's
Every query is automatically scoped to your organization at the database level. It's not something a developer can forget to add, and it's checked by continuous automated tests.
We never sell your data
Your business data is yours. We do not sell it, share it with advertisers, or use it for any purpose other than running your Incremenza account. This commitment is in our terms of service.
Smart Features
What we do, and do not do, with your data in My Advisor and automated features
Several Incremenza features use large language models: the My Advisor chat, the weekly briefing narrative, and parts of the transaction classification pipeline. Your business data is sent to AI providers (primarily Google Gemini, with Anthropic Claude as a fallback) to produce these outputs.
We use paid-tier API access on both providers. Both providers contractually agree not to use your data to train their models. Your data is processed for the specific request and not retained by the providers beyond the API call.
We minimize what leaves our systems. Personal details such as addresses and phone numbers are removed from merchant names before transmission. Only aggregated financial summaries are sent for insight generation, never individual transaction records. Account numbers, card numbers, and credentials are never sent.
You can disable AI-driven features per company in settings. Most automation (transaction classification fallback rules, recurring invoicing, dunning, anomaly detection) runs without AI.
For complete technical detail, read the legal security documentation →
Compliance
Compliance and certifications
We are direct about what we have today and what we are working toward.
GDPR
Data subject rights honored, including export and deletion. Our Data Processing Addendum is published, incorporates Standard Contractual Clauses, and takes effect automatically with no signature required.
CCPA
We honor California consumer privacy rights. We do not sell or share personal information.
PCI DSS
Card data handled exclusively by Stripe (PCI Level 1 service provider). Incremenza does not store card numbers.
SOC 2 Type II
Not currently held. We'll pursue certification once customer requirements call for it, and can complete security questionnaires in the meantime.
ISO 27001
Not currently held. Same approach: pursued if and when customers require it.
HIPAA
Not currently certified. Incremenza is not a HIPAA-covered entity. Healthcare businesses with PHI requirements should consult with us before connecting protected data.
Data Retention
What happens to your data when you leave
While your account is active, your data is retained continuously.
When you cancel, your data remains accessible for 90 days. You can reactivate within that window with all your data intact.
After 90 days, your personal and financial data is permanently deleted from our active systems. Backup data may persist up to 90 additional days before being purged from backup storage.
Some information may be retained longer if required by law (such as tax records, kept for 7 years).
Aggregated, anonymized usage data may be retained indefinitely for product improvement, but cannot be linked back to your specific account.
Common Questions
Security questions, answered
Incremenza is hosted on DigitalOcean via Laravel Forge, with primary servers in the United States. The database is MySQL with encryption at rest, and all connections use TLS 1.2 or above. Your business, financial, and customer data stay in the United States. Product usage analytics are stored separately, in the European Union.
A limited number of people have privileged access for support and infrastructure work, granted only when operationally necessary. All access is role-based and logged. Personnel with access to customer data are bound by confidentiality obligations and undergo background checks before being granted access.
We have a documented incident response procedure that includes detection, containment, investigation, communication, and post-incident review. Affected customers are notified within 48 hours of confirmed incidents involving their data. That's tighter than the 72 hours GDPR gives you to notify your own regulator, so you have time to meet your own obligations.
The legal security page contains the complete technical specifications: encryption algorithms, infrastructure details, monitoring procedures, and our full compliance posture. For specific questions not covered there, contact the security team.
🔒 Bank-level encryption · Read-only access · OAuth 2.0, no passwords shared · We never sell your data
Security
Questions about how we protect your data?
Take the free assessment to see what Incremenza will surface, or contact our security team for detailed answers about your specific compliance requirements.