Security & trust

Trust, earned on every entry

Propelly holds your most sensitive financial data. We treat that responsibility the way your auditors do — with encryption, granular access, and a complete, attributable record of every action.

SOC 2 Type II
Independently audited
GAAP
Compliant reporting
SOX-ready
Controls & segregation
GDPR & CCPA
Data privacy
How we protect your data

Security built into the ledger

Encryption everywhere

Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Keys are managed in a dedicated HSM and rotated automatically.

Granular access

Role-based permissions, SSO, and SCIM provisioning. Define exactly who can see and approve what — down to the account.

Complete audit trail

Every action — human or agent — is logged, timestamped, and attributable. Export an immutable trail for any period in seconds.

Agents within guardrails

Agents can only act inside the thresholds and policies you set. They never move money or post outside their explicit permissions.

Isolation & backups

Each customer's data is logically isolated, continuously backed up, and recoverable to any point in the last 30 days.

24/7 monitoring

Continuous threat detection, penetration testing, and a documented incident-response plan with defined SLAs.

"Automation should make the books more auditable, not less. Every figure in Propelly traces back to its source entry — and to whoever, or whatever, created it."
Our security commitment

Need our security docs?

We'll share our SOC 2 report, pen-test summary, and DPA under NDA — just ask in your demo.