Every product runs on the same living ledger.
Security for the financial data your business runs on.
Uplinq keeps your books continuously aligned - which means we hold the bank feeds, transactions, tax inputs, and documents your business operates on. That data deserves a higher bar, and a story you can verify.
Independent attestation of security controls, monitored with Drata.
Active confirm · period & scopeWhy this data is different
Accounting data isn't one thing. It's everything your business runs on.
To keep your books continuously aligned, Uplinq works across the most sensitive layers of your operation at once. Each carries its own risk - so each gets its own controls.
Bank & account data
Read-only feeds from the accounts money actually moves through.
Transactions
Every categorized line - the operating record of the business.
Tax inputs
The figures and elections that returns are built on.
Documents
Statements, invoices, and receipts uploaded for the record.
Identity records
Names, contacts, and other PII tied to the business.
Team workflows
Who did what, and the approvals in between.
Human review
Trained reviewers who see exceptions to confirm them.
Proof, not promises
Start diligence at the source of truth.
This is Uplinq's trust center. The security report is the fastest way to review our posture - live control status, monitored continuously with Drata. Everything below is the evidence behind it.
Security report
Uplinq's live control posture, tracked in Drata - the primary source for your diligence.
SOC 2 Type II
Independent audit of security controls, tested over a period of time.
Encryption
Data encrypted in transit and at rest across the platform.
Role-based access
Least-privilege access - each role sees only the data it needs.
Monitored infrastructure
Continuous logging and alerting on access and changes.
Data custody map
Follow one record through every control it passes.
Nothing skips a layer. From the moment a connection is made to the day data is deleted, each stage applies a specific, visible control.
Connect
Connections to your banks and tools use read-only access where supported.
Ingest
Transactions, documents, and tax inputs collected over encrypted transport.
Protect
Stored encrypted, with each business's data kept separate.
Interpret
AI categorizes and validates inside a defined control boundary.
Review
Trained reviewers confirm exceptions before they settle into the books.
Retain / Delete
Kept only per policy, exportable and deletable on request.
Connections to your banks and tools use read-only access where supported.
Every record moves through the same visible controls - connect to delete.
Infrastructure & encryption
A control stack you can read top to bottom.
Each layer is a specific control. Exact specifications are being confirmed with engineering so what's published matches what's enforced.
Encryption in transit
Traffic encrypted while moving between you, your banks, and Uplinq.
confirm · TLS versionEncryption at rest
Stored data encrypted on disk across the platform.
confirm · AES cipherKey management
Keys managed and rotated separately from the data they protect.
confirm · KMS & rotationLogging & monitoring
Access and system changes are logged.
Subprocessors
A small set of vetted providers helps run the platform.
The current, named subprocessor list is published in our security report and kept up to date there.
Diligence FAQ
The questions security teams actually ask.
Where should I start due diligence?
Right here. This page is Uplinq's trust center - and the security report at the top holds live control status, tracked in Drata, that you can review immediately.
Are you SOC 2 compliant?
We maintain SOC 2 Type II - an independent audit of security controls tested over a period of time. The report is available at the top of this page.
confirm · report period & scopeHow is my data encrypted?
Data is encrypted in transit and at rest across the platform, with keys managed separately from the data they protect.
confirm · TLS version, at-rest cipher, KMSDo you use my financial data to train AI models?
Your data is used to run your books inside Uplinq's control boundary - interpreted, validated, and reviewed by people. The exact model-training policy is being confirmed so the published statement matches engineering and legal reality.
confirm · training policy (legal + eng)Who can access my data, and how is it controlled?
Access is role-based and least-privilege: each role sees only the data it needs, backed by authentication and logging.
confirm · SSO / MFA / RBAC specificsWho are your subprocessors?
A small set of vetted providers for connectivity, hosting, storage, auth, monitoring, and AI processing. The current named list is published in our security report.
confirm · subprocessor listWhat happens in a security incident?
We follow a defined path - detect, contain, recover, communicate - and notify affected customers per policy and obligations.
confirm · IR timelines, DR, security contactHow do I export or delete my data?
You can request export and deletion of your data. Retention follows a published policy, and deletion runs on a defined timeline.
confirm · retention & deletion SLADo your diligence. We built this page to make it easy.
Start with the security report for live, verified evidence - then talk to us about your specific requirements.