Security & Data Protection

Last updated: September 2025

SyncBricks builds secure, cloud-based finance automation and integration services for Australian businesses. This statement describes the technical and organisational controls we apply to protect customer data, including accounting data accessed through connected systems such as Xero, MYOB (Business and AccountRight) and QuickBooks Online.

Our security programme is built around four principles: least-privilege access, customer consent, traceability, and separation of customer data. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). See our Privacy Policy for how personal information is collected and used.

Authentication & Access to Accounting Systems

  • --Connections to online accounting systems use OAuth 2.0 authorisation. Access is only established after an authorised customer administrator provides consent.
  • --We never collect or store accounting-platform usernames or passwords (such as Xero or my.MYOB login credentials).
  • --OAuth access and refresh tokens are encrypted and stored separately from application code.
  • --We request only the minimum scopes required for the features each customer activates, following the principle of least privilege.
  • --Customers retain control of their accounting account and can disconnect the integration at any time.

Encryption

  • --Customer data is encrypted in transit and at rest.
  • --TLS 1.2 or later is required for all application connections.
  • --Secrets and encryption keys are managed through a secure secrets-management service, separated from application code and configuration.

Access Control & Data Separation

  • --Multi-factor authentication is required for administrative access.
  • --Role-based access controls restrict access according to business need.
  • --Production access is limited to authorised personnel only.
  • --Customer environments and records are logically separated so one customer's data is not accessible to another.
  • --Application access and material actions are audit logged, producing clear trails of what was suggested, reviewed and approved.

Infrastructure & Operations

  • --Application hosting, encrypted storage, databases, secrets management, backups, monitoring and logging run on Amazon Web Services in the Australia region.
  • --Workflow orchestration runs on n8n, self-hosted and controlled by SyncBricks.
  • --We maintain backups, vulnerability management, security monitoring and incident-response procedures.
  • --Development practices consider the OWASP Top 10 and recognised infrastructure-hardening guidance, consistent with the Essential Eight framework.

Data Residency & Retention

  • --Customer data is hosted in Australia unless the customer and the relevant platform (such as Xero or MYOB) are informed and any required approval is obtained.
  • --Data retention is limited to the period required to provide the service, meet contractual requirements and satisfy applicable legal obligations.
  • --Customers may request disconnection, data export or deletion in accordance with the service agreement and applicable law.

Access to Customer Systems During Engagements

Our AI, automation and process discovery work can require access to customer systems and to activity data about individual users. That access is scoped and least-privilege, read-only where possible, time-boxed to the engagement and revoked on completion, and audit logged. We filter, anonymise or pseudonymise user-level data wherever identity is not needed for the outcome, and we return or securely delete engagement data once the work is done.

See our Data Processing & Retention page for full detail on how we handle systems access, user data and deletion after an engagement.

How We Use Customer & Accounting Data

Accounting data is used solely to provide the integration and automation services the customer selects. We do not:

  • --Sell customer or accounting data
  • --Use it for unrelated advertising
  • --Use customer accounting information to train public artificial intelligence models

No customer accounting data is submitted to consumer AI accounts. Any external AI or document-processing provider that may receive customer information is assessed, contractually controlled, disclosed to affected customers, and configured to prevent customer data from being used for general model training. Our current providers are listed on the Sub-processors page.

Human Approval & Traceability

Where our services prepare accounting entries, suggestions are presented to an authorised user for review. Only approved transactions are created or updated in the connected accounting system, which remains the system of record. Our initial finance-automation release does not lodge tax returns, initiate bank payments or make high-risk accounting decisions without human approval.

Reporting a Security Concern

If you believe you have found a security vulnerability or have a concern about how data is handled, please contact us at hello@syncbricks.com.au. We investigate all reports and respond promptly. We maintain incident-response procedures and will notify affected customers and relevant authorities where required by law.

Company: SyncBricks
ABN: 99 257 759 706
Email: hello@syncbricks.com.au
Location: Melbourne, Victoria, Australia

Questions About Security?

We're happy to walk through our controls, data handling and integration security in detail.

Get in Touch