NEW - SMALL BUSINESS REVENUE MOMENTUM REPORT Read it
10,457,361 Transactions aligned
Book a demo

Security for the financial data your business runs on.

Uplinq keeps your books continuously aligned - which means we hold the bank feeds, transactions, tax inputs, and documents your business operates on. That data deserves a higher bar, and a story you can verify.

SOC 2 Type IIEncryption in transit & at restRole-based accessMonitored infrastructure
View security report Live security report, monitored with Drata
SOC 2 Type II

Independent attestation of security controls, monitored with Drata.

Active confirm · period & scope

Why this data is different

Accounting data isn't one thing. It's everything your business runs on.

To keep your books continuously aligned, Uplinq works across the most sensitive layers of your operation at once. Each carries its own risk - so each gets its own controls.

Bank & account data

Read-only feeds from the accounts money actually moves through.

Transactions

Every categorized line - the operating record of the business.

Tax inputs

The figures and elections that returns are built on.

Documents

Statements, invoices, and receipts uploaded for the record.

Identity records

Names, contacts, and other PII tied to the business.

Team workflows

Who did what, and the approvals in between.

Human review

Trained reviewers who see exceptions to confirm them.

Proof, not promises

Start diligence at the source of truth.

This is Uplinq's trust center. The security report is the fastest way to review our posture - live control status, monitored continuously with Drata. Everything below is the evidence behind it.

Trust console Monitoring · continuous
Verified

SOC 2 Type II

Independent audit of security controls, tested over a period of time.

confirm · period & scope In the report
Enforced

Encryption

Data encrypted in transit and at rest across the platform.

confirm · cipher specifics How we encrypt
Enforced

Role-based access

Least-privilege access - each role sees only the data it needs.

Monitored

Monitored infrastructure

Continuous logging and alerting on access and changes.

confirm · monitoring stack
Published

Privacy & data handling

How we collect, use, retain, and delete data - including our DPA.

Data custody map

Follow one record through every control it passes.

Nothing skips a layer. From the moment a connection is made to the day data is deleted, each stage applies a specific, visible control.

01

Connect

Connections to your banks and tools use read-only access where supported.

OAuth / token confirm · no stored creds
02

Ingest

Transactions, documents, and tax inputs collected over encrypted transport.

TLS transportvalidated
03

Protect

Stored encrypted, with each business's data kept separate.

tenant isolation confirm · at-rest cipher
04

Interpret

AI categorizes and validates inside a defined control boundary.

boundedconfidence-scored
05

Review

Trained reviewers confirm exceptions before they settle into the books.

human-in-loopaudit log
06

Retain / Delete

Kept only per policy, exportable and deletable on request.

confirm · retentionconfirm · deletion SLA
Selected control Connect

Connections to your banks and tools use read-only access where supported.

Every record moves through the same visible controls - connect to delete.

Infrastructure & encryption

A control stack you can read top to bottom.

Each layer is a specific control. Exact specifications are being confirmed with engineering so what's published matches what's enforced.

Encryption in transit

Traffic encrypted while moving between you, your banks, and Uplinq.

confirm · TLS version

Encryption at rest

Stored data encrypted on disk across the platform.

confirm · AES cipher

Key management

Keys managed and rotated separately from the data they protect.

confirm · KMS & rotation

Logging & monitoring

Access and system changes are logged.

Subprocessors

A small set of vetted providers helps run the platform.

The current, named subprocessor list is published in our security report and kept up to date there.

View subprocessors

Diligence FAQ

The questions security teams actually ask.

Where should I start due diligence?

Right here. This page is Uplinq's trust center - and the security report at the top holds live control status, tracked in Drata, that you can review immediately.

Are you SOC 2 compliant?

We maintain SOC 2 Type II - an independent audit of security controls tested over a period of time. The report is available at the top of this page.

confirm · report period & scope
How is my data encrypted?

Data is encrypted in transit and at rest across the platform, with keys managed separately from the data they protect.

confirm · TLS version, at-rest cipher, KMS
Do you use my financial data to train AI models?

Your data is used to run your books inside Uplinq's control boundary - interpreted, validated, and reviewed by people. The exact model-training policy is being confirmed so the published statement matches engineering and legal reality.

confirm · training policy (legal + eng)
Who can access my data, and how is it controlled?

Access is role-based and least-privilege: each role sees only the data it needs, backed by authentication and logging.

confirm · SSO / MFA / RBAC specifics
Who are your subprocessors?

A small set of vetted providers for connectivity, hosting, storage, auth, monitoring, and AI processing. The current named list is published in our security report.

confirm · subprocessor list
What happens in a security incident?

We follow a defined path - detect, contain, recover, communicate - and notify affected customers per policy and obligations.

confirm · IR timelines, DR, security contact
How do I export or delete my data?

You can request export and deletion of your data. Retention follows a published policy, and deletion runs on a defined timeline.

confirm · retention & deletion SLA

Do your diligence. We built this page to make it easy.

Start with the security report for live, verified evidence - then talk to us about your specific requirements.