- MEMBER
- View and create
- ACCOUNTANT
- View, create, edit, export
- MANAGER
- …plus delete and manage the team
- ADMIN
- …plus invite administrators
- OWNER
- …plus manage the organisation and billing
Five role tiers, checked per permission.
Guarantees, with the mechanism attached.
Anyone can claim to be compliant. These are the eight places the platform enforces it, and how — because under an audit the mechanism is the only part that matters.
Security & compliance in full- FTA / SEQ
Gapless sequential numbering
Document numbers are issued in an unbroken series, per organisation and per document type. No duplicates, no missing numbers, even when two people issue at the same moment.
PostgreSQL FOR UPDATE row lock on the sequence record
- FTA / TLV
TLV QR code on every tax document
Each invoice PDF carries an FTA-format TLV QR code, generated from the document itself rather than pasted in as an image.
Generated at render time, across all six PDF templates
- FTA / VAT
Five VAT treatments, per line
Standard-rated, zero-rated, exempt, reverse-charge and out-of-scope — computed line by line, in inclusive or exclusive pricing, and rolled into the return.
A single VAT engine shared by invoices, bills and credit notes
- FTA / 5YR
Five-year retention by design
Deleting a document removes it from your views without destroying it. The record and its audit history survive for the statutory retention window.
Soft deletes on every financial document
- GL / LOCK
Closed periods stay closed
Once an accounting period is closed, the ledger refuses new entries against it. Voiding a document posts a mirror-reversal instead of editing history.
Period resolution inside the only journal writer
- SEC / ISO
Row-level tenant isolation
Every query is scoped to your organisation before it reaches the database. One business can never read another's records, including through a direct record lookup.
Organisation filter injected at the data-access layer
- SEC / 2FA
Two-factor authentication, mandatory
Every account carries TOTP-based second-factor sign-in. Access inside the organisation is governed by five escalating role tiers.
MEMBER · ACCOUNTANT · MANAGER · ADMIN · OWNER
- SEC / LOG
Before-and-after audit trail
Every mutation records what changed, who changed it and when — the prior state alongside the new one, not just an event name.
Audit log written on every write path
8
Payment methods
Stripe, Tabby, Tamara, card, bank, cheque, cash, PayBy
5
VAT treatments
Standard, zero-rated, exempt, reverse-charge, out-of-scope
6
PDF templates
Each one FTA-compliant, each one bilingual
2
Languages
English and Arabic, with full right-to-left layout
Four things that hold whether or not anyone is watching.
Tenant isolation
Every query is scoped to your organisation before it reaches the database — including a direct record lookup, which is re-validated after the fetch rather than trusted.
Mandatory two-factor
TOTP second-factor sign-in on every account, with sessions issued as signed tokens and cookie flags set centrally rather than per route.
Scoped integration keys
The Connected Apps API authenticates with per-app secrets and enforces module scopes, an allowed-method list and IP whitelisting on every call.
Before-and-after audit trail
Each mutation records the prior state alongside the new one, with the user and timestamp — so a change can be read, not just detected.
What an auditor asks first.
Your records sit in a shared database with row-level isolation by organisation. Financial documents are soft-deleted rather than destroyed, so the record and its audit history survive the five-year retention window the FTA expects.
Start where you are
Issue one compliant invoice. Then look at the ledger.
Fourteen days of every feature, no card, and nothing to migrate before you can see whether it works the way you do.
English & Arabic · AED and multi-currency · UAE-built for FTA rules