Security & trust

Built read-only, on purpose.

Postlock handles financial data, so safety is a design decision, not an afterthought.

Read-only access

Postlock requests read-only Xero permissions and nothing else. It is technically incapable of posting, editing or deleting anything in your ledger.

No write scopes, ever

We will never ask for write access. When Postlock finds a problem, it names it - a human makes the change in Xero.

Minimal data

We pull the balance sheet and the document history needed to show what changed. No card data, no payroll, no payments.

Encrypted in transit and at rest

All traffic runs over HTTPS; stored data is encrypted at rest by our hosting provider. Your Xero access token is kept server-side and removed the moment you disconnect.

No AI, at all

There is no AI anywhere in Postlock. Nothing reads your ledger but deterministic code, and your data is never used to train models - there is no model here to feed.

Honest about our stage

Postlock is in early access. Formal certifications (e.g. SOC 2) are on the roadmap; we'll say plainly where we are when you ask.

The AI question

Where's the AI? There isn't any.

Every close tool now leads with AI. We lead with the opposite - deliberately, and for three reasons an accountant will recognise.

Your ledger isn't a prompt

Could AI spot things in a ledger? Genuinely, yes: "flag any subscription over £5,000" is a fair example. But a written rule does that too, and the rule shows its working: you can read it, test it, and know it ran identically last month. Everything a close-integrity check needs has a plain-rules way of doing it - so your financial data never has to be sent to a model to earn its keep, and here it never is.

Deterministic means auditable

Every check Postlock runs is written-down logic: the same inputs produce the same answer, every time, and a reviewer can re-perform it by hand. That's what makes the output usable as audit evidence. "The model flagged it" is not a working paper.

No meter under the price

AI features run on metered compute, and that meter sits somewhere under the subscription price. Postlock's checks are ordinary code - they cost pennies to run at any scale. Whatever happens to AI pricing happens to other tools' cost base, not ours.

It's not that we couldn't bolt AI on. It's that a close-integrity tool is the wrong place for one - you want a witness with a perfect memory, not a colleague with opinions. This is just a good tool, on purpose.

Where your data lives

The data-handling picture, plainly.

The questions an accountant should ask before connecting a ledger to anything - answered without a sales filter.

Hosting & region

Postlock runs on Render, a managed cloud platform, currently in a US region. We say that plainly because you should know it: UK GDPR permits it with the standard safeguards, and a move to a UK/EU region is planned as we grow. Stored data is encrypted at rest by the platform; all traffic is encrypted in transit (HTTPS, HSTS).

Retention & deletion

Your data stays until you say otherwise. Export the full account (every snapshot, reconciliation, memo and change log) in one click at any time. Deleting the account erases its data and uploaded evidence immediately - self-serve, no email chain, no retention lawyering. Disconnecting Xero deletes the access token on the spot.

Subprocessors

Four, all boring on purpose: Render (hosting), Stripe (payments - card details go to Stripe, never to us), Resend (transactional email, EU region), Cloudflare (DNS and inbound email routing). No analytics trackers, no ad pixels, no data brokers. DPA available on request at hello@postlock.co.

Questions from your IT or security team?

We're happy to talk through how it works.

Contact us