Security
Your books and your inbox, handled with care.
Northdue connects to two of the most sensitive systems a business has. This page sets out exactly what we can access, how we protect it, and where we stand today, including what we haven't done yet.
What we access
Each connection asks for the least its job needs. You grant it on the provider's own sign-in page and can revoke it there, or disconnect from your Connections page, at any time.
| Connection | Permission | What Northdue does with it |
|---|---|---|
| QuickBooks Online | com.intuit.quickbooks.accounting | Reads invoices, customers, payments and invoice PDFs. Never writes. |
| Xero | accounting.invoices.read accounting.contacts.read accounting.payments.read | Reads invoices, contacts and payments. |
| QuickBooks Desktop | Intuit Web Connector | Read-only queries for open invoices, customers and payments, hourly. |
| Gmail / Google Workspace | gmail.send gmail.readonly | Sends the emails you approve. Reads new mail to find your customers' replies. |
| Microsoft 365 / Outlook | Mail.Send Mail.Read User.Read | Sends the emails you approve. Reads new mail to find replies. Reads your address. |
Your mailbox
Mailbox access is what people worry about most, so here's exactly how it's used.
- Sending: only emails a person has approved, or that match the approval rules you set, go out from your address.
- Reading: every new message is checked automatically, except sent mail, drafts, spam and trash, which are never read.
- What's kept: replies from your customers, stored with their account and read by the AI, and mail from other senders that mentions an invoice or payment, kept for our team to match to a customer.
- Everything else is skipped. It isn't stored or sent to the AI. We keep only a marker so it isn't checked twice.
- Nothing is changed. Northdue can't delete, move, label or mark anything as read in your mailbox.
How data is protected
- In transit: every page and connection uses HTTPS, and browsers are told to use nothing else.
- At rest: data is stored on encrypted disks, and so are the disks' automatic daily snapshots.
- Connections: the sign-in tokens for your books and mailbox are encrypted a second time (AES with an HMAC signature) with a key kept in the server's protected settings, not with the data.
- Backups: a copy is made every night, and seven are kept by default. The server's settings file and sign-in key are left out, and connections inside backups stay encrypted.
- Your customers' pages: each link is signed and can't be guessed, and you can replace one at any time.
Sign-in and access
- Passwords are stored only as salted hashes. Repeated wrong passwords lock the sign-in for ten minutes.
- Two-step sign-in with an authenticator app is available to everyone, and an owner can require it for all users.
- Sessions are recorded on the server and end after 12 hours by default, on signing out, and whenever the password or two-step sign-in changes.
- Roles: client users only ever see their own company, never other clients, billing, calls or our team's internal tasks.
- Audit log: every approval, rejection, edit, setting change and fee invoice is recorded with the person's name.
- The web app uses anti-forgery tokens on every form and strict browser security headers.
AI and your data
Northdue uses Claude, from Anthropic, through Anthropic's commercial API to draft emails and to understand replies. Here's what it sees and what it doesn't.
- To draft an email: your company and sender name, the tone you've chosen, the customer's company name and contact's first name, invoice numbers, the total past due, how many days late, how many emails were already sent, any promised date, and the reply-by date.
- To understand a reply: the customer's message and its subject, without the history it quotes where that can be separated, and the open invoice numbers on that account.
- Not sent: your bank or remittance details, passwords, or your other mail.
- No training: we don't train AI models on your data. Under Anthropic's commercial terms, Anthropic doesn't train its models on it either, and it deletes API inputs and outputs within 30 days, except where content is flagged for a usage-policy review or the law requires otherwise.
- Your choice: at your request we switch AI drafting off for your company. Templates and rules then do the same jobs.
Who can see your data
Northdue is a service, so people are involved by design: when you ask us to, our team approves emails, reads customers' replies and handles tasks for you, and matches mail that may be about an invoice to the right customer. Beyond that, Northdue staff look at your data only to provide the service you've asked for, to keep it secure, or when the law requires it. We never sell your data or use it for advertising.
Where it runs
These are the companies that process data for Northdue. Your own accounting and email providers are connected with your permission and aren't listed here.
| Company | What for | Security |
|---|---|---|
| Render | Hosting the app and its data, in Virginia, US | SOC 2 Type 2 and ISO 27001 (details) |
| Anthropic | Drafting emails and understanding replies | Anthropic's trust center |
| Vapi | AI phone calls, only if you turn them on | SOC 2 Type II (details) |
Where we stand
We're a young company, so here's the honest version.
- Northdue itself isn't SOC 2 audited yet. The infrastructure we run on is, and we'll tell you here when our own audit is done.
- Gmail connections require an independent security assessment every year before any app can read Gmail for everyone. We'll publish the result here.
- Questions about how we handle data? Write to privacy@northdue.com.
Report a vulnerability
If you think you've found a security problem in Northdue, please email security@northdue.com with the details and how to reproduce it. We aim to acknowledge reports within two business days and will keep you updated while we fix it.
Please don't access other people's data, disrupt the service, or share the issue publicly before it's fixed. We won't take action against good-faith research that follows these rules.