Back to Home
Trust Center

Controls for sensitive financial and operational information.

A transparent view of what is implemented, what you control, and what remains your responsibility.

Implemented controls

Designed to protect financial and operational records.

Encryption in transit and at rest

Data is encrypted while moving between systems and while stored.

Tenant isolation

Records are isolated at the data layer by organization and owner.

Owner-controlled roles

The plan sets the ceiling and authorized owners decide what each person may open.

Two factor authentication

Two factor authentication is available as an additional account security control.

Private document access

Access controls for documents that should not be broadly visible.

Device session handling

Sessions are registered and can be reviewed on supported devices.

Audit trail

Security-sensitive activity is recorded in a durable history for review and accountability.

GDPR and CCPA data export

Export tools support applicable access and portability requests.

GDPR and CCPA deletion

Account deletion can be scheduled with a recovery period before removal.

What we do not claim

No certification wall.

FiscoPoint does not claim SOC 2, PCI DSS, ISO 27001, or any other independent security certification. Privacy controls support GDPR and CCPA requests where applicable, but regulatory obligations depend on the customer, use case, and jurisdiction. No online system can promise zero vulnerabilities or absolute security.
Your responsibility

What stays with you.

  • Choose who receives master administrator and sub admin privileges.
  • Review AI generated content before relying on or sending it.
  • Confirm that regional, tax, payroll, and legal requirements are met with qualified professionals.
  • Keep credentials, devices, and shared invitation links under control.
Teams, roles, and access

The plan sets the ceiling. The owner sets access.

  • The plan sets the maximum modes, features, and user capacity available to the workspace.
  • The owner decides which modes, records, and working areas each person may open.
  • Administrators can grant only the privileges they are authorized to manage.
  • Members and viewers receive role-appropriate access.
  • Invitations can be limited to the relevant modes and working areas.
  • No person can raise their own access.

Access control is a product capability and is not presented as an independently certified identity-governance system.