Security & Trust at EveryCent
Your books run on EveryCent. Here's how we protect them.
EveryCent is built for small-business financial data — so security is engineered in, monitored continuously, and verified independently. This page is generated from our live compliance system, not a marketing document.
Independent verification
Third-party and continuously-monitored signals you can verify yourself.
Independently examined by Atom Assurances LLC, Certified Public Accountant Firm. The full report is available to prospects and customers under NDA — request it below.
Doing a security review of EveryCent?
Send us your questionnaire (SIG, CAIQ, or your own) — our Trust team answers from our live controls, typically within one business day.
Ask about EveryCent's security
Get an instant, cited answer from our live controls and policies — no questionnaire required.
Answers cover our public security posture only. Need a full SIG / CAIQ completed? Contact security@everycent.ai →
Our controls
23 active controls, monitored continuously and grouped by area. Expand any category to see what we enforce.
Data Protection & Access Control
Encryption, least-privilege access, and the controls that keep customer financial data private.
6
▾
Infrastructure, Availability & Recovery
Hosting, backups, point-in-time recovery, and restore drills that keep your books available and recoverable.
6
▾
Change Management & Secure SDLC
Every code change passes security gates before it reaches production.
5
▾
Governance, Monitoring & Response
Policies, risk management, vendor oversight, penetration testing, and incident response.
6
▾
Subprocessors
Notify me of changesThird-party services that may process EveryCent customer data, and what they are used for. Each is tracked in our vendor risk register with an annual review.
Documents
Public documents download directly; NDA-gated material is shared after a quick access request.
Access requests are reviewed quickly; granted links are one-time, expiring, and audit-logged.
Frequently asked questions
The questions security reviewers ask us most often.
Where is EveryCent data stored? ▾
All customer data is stored in the United States on Google Cloud Platform (region us-central1). We do not replicate customer data outside the US.
How is data encrypted? ▾
Data is encrypted with AES-256 at rest across our Google Cloud infrastructure and TLS 1.2+ in transit. Credentials and sensitive personal data get an additional layer of application-level field-level AES-256-GCM encryption.
What is your data retention & deletion policy? ▾
Customer data is retained for the life of the account and deleted in accordance with our Data Processing Addendum (DPA) after termination, subject to legal and tax retention obligations. You can request export or deletion at any time by emailing security@everycent.ai.
How and when are security incidents disclosed? ▾
Our incident response policy commits to notifying affected customers without undue delay and within 72 hours of confirming a reportable security incident, with follow-up updates as our investigation progresses.
Who are your subprocessors, and will I be notified of changes? ▾
Our current subprocessors are listed on this page, each tracked in our vendor risk register with an annual review. You can subscribe to subprocessor change notifications using the link in the Subprocessors section.
Do you offer an API and a status page? ▾
Yes. EveryCent has a documented REST API (Bearer-token auth, rate-limited, with signed webhooks) and continuously monitors uptime. Reach us at security@everycent.ai for status or API access questions.
Security questions, responsible disclosure, or questionnaire requests: security@everycent.ai
This page is generated live from EveryCent's compliance system.