1. Security Program
Backline maintains administrative, technical, and organizational measures proportionate to the Service and information involved. Controls evolve with the product, threat environment, and provider capabilities. This page is a current overview, not a certification, warranty, service-level agreement, or promise that an incident cannot occur.
2. Data Protection
- HTTPS/TLS protects supported network traffic in transit.
- Managed infrastructure providers protect stored application and database data with encryption at rest.
- QuickBooks Online OAuth credentials use the application’s encrypted grant store. Storage and access controls for other enabled services depend on the configured integration.
- Secrets are kept outside source code in managed environment configuration, and public-browser code is not intended to receive server credentials.
- Backups and provider recovery features support continuity, subject to tested procedures and applicable service terms.
3. Identity and Access
- Managed authentication, authenticated sessions, and organization-aware application authorization restrict access.
- Roles and permissions are designed to limit users and personnel to authorized functions and customer workspaces.
- OAuth state and callbacks are validated, and supported financial connections use provider authorization flows rather than collecting provider passwords.
- Customer administrators control invitations, membership, roles, connected services, and many recipient or approval decisions.
Application authorization checks enterprise and entity access. Scoped database transactions also apply PostgreSQL row-level security. Customers with prescribed security requirements should verify the deployed controls and address their requirements in a signed agreement before use.
4. Application and Infrastructure Safeguards
- Central browser-security headers include content-security, transport-security, anti-framing, MIME-sniffing, referrer, and permissions policies.
- Code review, automated type and lint checks, unit and integration tests, secret scanning, API-route inventory, and security-control checks support change management.
- Application logging, error monitoring, security events, dependency review, and uptime signals support investigation and response.
- Public webhooks and machine-to-machine routes use provider signatures, scoped credentials, or other route-appropriate authentication where implemented.
- Human review and authorization controls are designed to bound automated accounting actions and prevent an agent from approving its own work.
5. Connected Financial Platforms
myBBS includes QuickBooks Online and Xero accounting adapters. Available connections depend on the configured service. Enabled authorization flows use provider consent rather than collecting accounting-platform passwords. For QuickBooks Online, Backline requests the Accounting scope and does not request an Intuit password or the QuickBooks Payments scope. Bank connections use an approved financial-data provider, and Backline does not receive online-banking passwords. Customers can revoke supported connections through the provider or request disconnection and deletion from Backline.
6. Personnel and Service Providers
Access is granted based on business need and restricted through provider and application controls. Service providers support hosting, data, identity, monitoring, communications, workflow, financial connectivity, and optional automated features. Providers are expected to process information for contracted purposes and applicable obligations. See Subprocessors & Service Providers.
7. Secure Development and Known Limitations
Backline tracks production-readiness findings and remediates them according to severity. A successful test or control reduces risk but does not prove the absence of vulnerabilities. Before broad or regulated deployment, customers should complete their own risk assessment and contact Backline about any required independent assessments, certifications, penetration tests, recovery objectives, data residency, regulated-data handling, or industry-specific contractual terms. We will confirm what documentation and commitments are available for the proposed scope.
8. Customer Responsibilities
- Use unique accounts and secure authentication methods; never share sessions or verification codes.
- Grant minimum necessary access, review membership regularly, and promptly remove departed or reassigned users.
- Keep devices, browsers, email accounts, and connected platforms secure and current.
- Verify account details, approvals, report recipients, exports, and automated suggestions before acting.
- Do not place passwords, private keys, bank credentials, payment-card security codes, or prohibited regulated data into free-text fields or support email.
- Promptly report suspected compromise, misdirected data, or unusual activity.
9. Incident Response
Backline investigates suspected incidents, works to contain and remediate confirmed issues, preserves relevant records, and notifies affected customers or authorities when required by law or contract. Notification timing and content depend on the facts, investigation, provider coordination, and legal requirements.
10. Responsible Disclosure
If you believe you found a vulnerability, avoid accessing, changing, downloading, or retaining data that is not yours; do not disrupt availability, use social engineering, or test against third-party systems. Email admin@backlinebusinesssolutions.com with the affected URL, non-sensitive reproduction steps, and potential impact. Do not include credentials or live financial data. We will acknowledge good-faith reports and coordinate appropriate validation and remediation. Testing authorization must be obtained in writing in advance.
11. Security Documentation
Customers may request a security questionnaire, available architecture information, or contractual security terms. Disclosure may require confidentiality protections and may be limited to protect customers and systems.

