Skip to content
Security & compliance

Every guarantee on this page names how it is enforced. That is the only version worth reading before you put five years of financial history into someone else's software.
MEMBER
View and create
ACCOUNTANT
View, create, edit, export
MANAGER
…plus delete and manage the team
ADMIN
…plus invite administrators
OWNER
…plus manage the organisation and billing

Five role tiers, checked per permission.

Compliance

Guarantees, with the mechanism attached.

Anyone can claim to be compliant. These are the eight places the platform enforces it, and how — because under an audit the mechanism is the only part that matters.

Security & compliance in full
  1. FTA / SEQ

    Gapless sequential numbering

    Document numbers are issued in an unbroken series, per organisation and per document type. No duplicates, no missing numbers, even when two people issue at the same moment.

    PostgreSQL FOR UPDATE row lock on the sequence record

  2. FTA / TLV

    TLV QR code on every tax document

    Each invoice PDF carries an FTA-format TLV QR code, generated from the document itself rather than pasted in as an image.

    Generated at render time, across all six PDF templates

  3. FTA / VAT

    Five VAT treatments, per line

    Standard-rated, zero-rated, exempt, reverse-charge and out-of-scope — computed line by line, in inclusive or exclusive pricing, and rolled into the return.

    A single VAT engine shared by invoices, bills and credit notes

  4. FTA / 5YR

    Five-year retention by design

    Deleting a document removes it from your views without destroying it. The record and its audit history survive for the statutory retention window.

    Soft deletes on every financial document

  5. GL / LOCK

    Closed periods stay closed

    Once an accounting period is closed, the ledger refuses new entries against it. Voiding a document posts a mirror-reversal instead of editing history.

    Period resolution inside the only journal writer

  6. SEC / ISO

    Row-level tenant isolation

    Every query is scoped to your organisation before it reaches the database. One business can never read another's records, including through a direct record lookup.

    Organisation filter injected at the data-access layer

  7. SEC / 2FA

    Two-factor authentication, mandatory

    Every account carries TOTP-based second-factor sign-in. Access inside the organisation is governed by five escalating role tiers.

    MEMBER · ACCOUNTANT · MANAGER · ADMIN · OWNER

  8. SEC / LOG

    Before-and-after audit trail

    Every mutation records what changed, who changed it and when — the prior state alongside the new one, not just an event name.

    Audit log written on every write path

8

Payment methods

Stripe, Tabby, Tamara, card, bank, cheque, cash, PayBy

5

VAT treatments

Standard, zero-rated, exempt, reverse-charge, out-of-scope

6

PDF templates

Each one FTA-compliant, each one bilingual

2

Languages

English and Arabic, with full right-to-left layout

Platform controls

Four things that hold whether or not anyone is watching.

Tenant isolation

Every query is scoped to your organisation before it reaches the database — including a direct record lookup, which is re-validated after the fetch rather than trusted.

Mandatory two-factor

TOTP second-factor sign-in on every account, with sessions issued as signed tokens and cookie flags set centrally rather than per route.

Scoped integration keys

The Connected Apps API authenticates with per-app secrets and enforces module scopes, an allowed-method list and IP whitelisting on every call.

Before-and-after audit trail

Each mutation records the prior state alongside the new one, with the user and timestamp — so a change can be read, not just detected.

Questions

What an auditor asks first.

Your records sit in a shared database with row-level isolation by organisation. Financial documents are soft-deleted rather than destroyed, so the record and its audit history survive the five-year retention window the FTA expects.

Start where you are

Issue one compliant invoice. Then look at the ledger.

Fourteen days of every feature, no card, and nothing to migrate before you can see whether it works the way you do.

English & Arabic · AED and multi-currency · UAE-built for FTA rules