Security at EntryRocket
You're trusting us with your financial data. Here's how we keep it safe.
We take security seriously because we know we're handling sensitive financial information. Here's what we do to make sure your data stays protected — from how we host the application to how we handle your files.
Secure Infrastructure
EntryRocket runs on Heroku's cloud platform, which gives us solid infrastructure security out of the box:
- SOC 2 Type II certified hosting environment
- Automated daily backups with point-in-time recovery
- Automatic security patches and platform updates
- Network isolation between applications
- Infrastructure-level DDoS mitigation provided by the hosting platform
Encryption Everywhere
All data is encrypted both in transit and at rest:
- TLS 1.2+ encryption for all connections to our servers
- AES-256 encryption for data stored in our database
- Email processing supports TLS encryption
- HTTPS only - we enforce secure connections on all endpoints
Secure Xero Integration
We connect to Xero using OAuth 2.0 — the same standard used by all major services:
- OAuth 2.0 authentication - we never see or store your Xero password
- Scoped permissions - we only request access required to process your documents
- Token-based access with automatic refresh and secure storage
- Revoke anytime - disconnect EntryRocket from your Xero account instantly
We're a verified Xero App Partner — our integration has been reviewed and approved by Xero's team.
Authentication & Access Control
We keep your account locked down:
- Secure password hashing using bcrypt with strong salt
- Session management with automatic timeout and secure cookies
- Email verification for all new accounts
- Organization-level isolation - your data is completely separate from other customers
Payment Security
All payments are processed securely through Paddle, our Merchant of Record:
- PCI DSS Level 1 compliant payment processing
- We never store your credit card details - Paddle handles all payment data
- Paddle's secure checkout includes fraud detection and prevention
Your Data, Your Control
It's your data — you're in control:
- Minimal data retention - we only keep what's necessary for the service
- No data selling - we never sell or share your data with third parties
- Data inquiries - contact us about any data we hold about you
- Account deletion - request removal of your account and associated data
Application Security
We follow security best practices in how we build the application:
- CSRF protection on all forms and state-changing requests
- SQL injection prevention using parameterized queries
- XSS protection with automatic output escaping
- Security scanning tools for code analysis and dependency vulnerability detection
Monitoring & Operations
We monitor the platform to keep things running smoothly:
- 24/7 uptime monitoring with automated alerting
- Error tracking for issue detection and resolution
- Server logging for operational oversight and troubleshooting
Got Security Questions?
If you'd like to know more about how we handle security, or want to report a concern, just reach out.
Contact UsReady to Give It a Try?
Pick a plan to get started, or book a free call so we can walk you through how it works.