Home › Security

Security overview

Your contacts and your books are protected the same way we protect our own

Tormano connects to your accounting system, so security is the precondition for the whole product. Here is how we protect it.

Application security

Passwords nobody can read

Passwords are hashed with argon2id and are never stored in readable form. Nobody at Tormano can look one up, and nobody can recover one.

Two-factor sign-in

Two-factor sign-in works with any standard authenticator app. Single sign-on through SAML is available on our top plans. See which plans include it.

Role-based access

Access is controlled by role on every plan, so each person reaches the records their job needs and nothing else.

Your data is yours alone

Every request is scoped to your organization. Nobody outside it can reach your records, and that is enforced by the software rather than by convention.

Sign-in attack protection

Sign-in and API requests are rate-limited, which blunts password-guessing and credential-stuffing attacks before they get anywhere.

Protected in the browser

Every page is served over HTTPS, with a content security policy and clickjacking protection in place.

Data protection

Encrypted in transit

All traffic is encrypted with TLS, including the traffic between Tormano and QuickBooks, Stripe, and every connected integration.

Encrypted connection keys

The keys that connect Tormano to QuickBooks, Xero, and every other integration are encrypted with AES-256 before they are stored.

Card data never lands here

Payments run on Stripe. Card numbers are entered into Stripe-hosted fields and never pass through or persist on Tormano's servers.

Tamper-proof audit trail

The audit log is written once and cannot be edited or deleted by anyone, including organization owners. It is on every plan.

U.S. hosting

Production runs in a data center in Ashburn, Virginia, in the United States.

Privacy requests

Export or delete a person's data on request, under GDPR and CCPA. Our DPA, subprocessor list, and privacy policy are public.

Backups and continuity

Restore to any point in time

Every change to the database is captured continuously, so your data can be restored to any moment rather than to last night.

Nightly encrypted offsite backups

Full backups run nightly, are encrypted before they leave our servers, and are copied to independent offsite storage.

Restored and checked every week

A backup you have never restored is a hope rather than a plan, so a backup is restored and verified every week. Live availability is on our status page, with the uptime history and incident record.

Responsible disclosure

Found a vulnerability?

We want to hear about it, quietly and quickly. Email security@tormano.com and we'll respond promptly. Our disclosure policy is published in the standard security.txt format.

What we ask, and what we promise

Give us reasonable time to fix an issue before public disclosure. In return, we will not take legal action against good-faith security research.

Questions about any control on this page? Ask us.

See Tormano with your own data

Connect QuickBooks, import your records, and judge it on your real workflows.

No credit card required. Every feature unlocked for the full 14 days.