1. Approach
BookOS is built using security-focused infrastructure and vendors that may maintain independent security certifications such as SOC 2. BookOS itself does not claim such certifications unless it has completed an independent audit and published it.
2. Encryption
Data is encrypted in transit using TLS and at rest using industry-standard mechanisms supplied by our hosting and database providers.
3. Access controls
We enforce role-based access and least-privilege principles inside BookOS. Multi-factor authentication is available for sensitive actions; we recommend enabling it on every account.
4. Activity logging
User and AI actions are logged so changes are reviewable. Workspace-level activity logs surface in the product.
5. Vendor and subprocessor review
We review vendors for security posture before onboarding and contractually require appropriate confidentiality and security terms. The current list is on our Service providers page.
6. Bank-credential handling
BookOS does not store bank login credentials. Where bank connections exist, they are handled by external aggregator providers you authorize directly. BookOS does not hold customer funds.
7. Payment-credential handling
Payment-method details for BookOS subscription billing are handled by our PCI-compliant payment processor. BookOS does not store full card numbers. See our subprocessor list for the current processor.
8. Monitoring and incident response
We monitor for anomalous access patterns, failed authentication, and abuse. We maintain an incident response process and will notify affected customers of material incidents as required by law and contract.
9. Secure development
We follow secure-coding practices, code review, and dependency and vulnerability monitoring.
10. Backups and continuity
We maintain backup and recovery procedures to protect availability and ensure data can be restored.
11. Data deletion controls
You can request data deletion from your workspace settings or by contacting support, subject to legal retention obligations.
12. Vulnerability disclosure
We welcome responsible disclosure of security issues. Contact support with details so we can investigate. We do not currently operate a public bug bounty program.

Version history

Track changes over time
v1.0Initial publication · May 12, 2026