Trust & Architecture

Security & Data Integrity

How BusinessOS safeguards enterprise accounting data and financial operations.

🛡️

Server-Side Session Authentication

All user sessions are backed by Better Auth with cryptographically signed, HttpOnly cookies. We never store raw passwords or trust client-provided user IDs.

🏢

Strict Multi-Tenant Boundaries

Every database query is automatically scoped to the authenticated Business ID. Users cannot access counterparties, transactions, or statements across business tenants.

⚡

Database Transaction Atomicity

Financial ledger writes and `PartyBalance` snapshot recalculations are executed within atomic PostgreSQL transactions (`prisma.$transaction`). Either all updates succeed or the entire operation rolls back.

📝

Immutable Audit Trails

All party creation, profile edits, ledger postings, and transaction reversals are recorded to an append-only `AuditLog` table with IP addresses, timestamps, and user attribution.

Integer Minor-Unit Precision

Traditional floating-point arithmetic introduces rounding drift (e.g., `0.1 + 0.2 = 0.30000000000000004`). BusinessOS stores all financial values as 64-bit integer minor units (`BigInt`) representing paise or cents, ensuring zero precision loss across millions of ledger entries.

Encryption at Rest and in Transit

All network communication with BusinessOS uses TLS 1.3 encryption. Database persistence through Neon PostgreSQL uses AES-256 encryption at rest.

Responsible Disclosure

If you discover a vulnerability or security flaw, please contact our security team directly at support@mail.businessos.rauhansheikh.com.