Access Control Policy
Effective June 9, 2026
Caipibara provides bookkeeping, reconciliation, and tax-preparation software for Canadian accounting firms. This Access Control Policy describes how we govern access to our production systems and to the data they hold. It applies to all personnel (employees and contractors), production systems, and the cloud environment in which the service runs.
Policy statement
A documented access-control policy is maintained and enforced. Access to systems and to client data is granted on a least-privilege basis — individuals and services receive only the access required to perform their role or function, and nothing more.
Role-based access control (RBAC)
Access is assigned by role rather than to individuals ad hoc. Roles are defined for application users (accounting-firm staff, whose access is scoped to their own firm and clients) and for internal personnel (such as engineering and operations roles). Each role carries the minimum privileges necessary for its responsibilities.
Identity and access management
Access is managed through centralized identity and access management. Infrastructure and cloud resources are controlled through our cloud provider’s IAM, and administrative access is governed centrally. Access is individually attributable; shared or generic privileged accounts are avoided.
Authentication
Application sign-in uses one-time-passcode (OTP) email verification with server-side sessions (httpOnly cookies with defined expiry). Administrative and cloud access requires multi-factor authentication. Secrets, OAuth tokens, and bank-connection tokens are encrypted before storage.
Provisioning and de-provisioning
Access is granted only upon role assignment with appropriate approval. When an employee or contractor is terminated or transferred to a different role, their access is promptly modified or revoked as part of a defined offboarding process, so that access always reflects a person’s current role.
Periodic access reviews and audits
Access rights are reviewed and audited on a periodic basis to confirm they remain appropriate, and access that is no longer needed is removed. Security-relevant actions are recorded in audit logs to support monitoring, review, and investigation.
Multi-tenant data isolation
The platform is multi-tenant. Every data request is scoped to the authorized firm, so one firm cannot access another firm’s data.
Encryption and data protection
Data is hosted in Canada (AWS ca-central-1) in support of PIPEDA, and is encrypted in transit (TLS) and at rest. OAuth and bank-connection tokens and other secrets are encrypted before they are stored.
Enforcement and review
Failure to comply with this policy may result in revocation of access and other appropriate action. This policy is reviewed periodically and updated as our systems and practices evolve; the effective date above reflects the latest version.
Contact
Questions about this policy: johnyin@synervex.ai.