Trust

Where your ledger lives, who can see it, and what a model is allowed to see.

Plametrix holds client general ledgers, so this page says plainly how they are handled. Last reviewed October 3, 2026. Security questionnaires go to info@plametrix.com and are answered in full.

The numbers

  • No language model computes a figure. Statements, covenant tests, forecasts, the lender package and the board pack are produced by deterministic code running against your ledger.
  • Every figure carries a query back to the ledger line that produced it. In the workspace, click a number and read the postings.
  • Every pack figure is independently re-derived before the pack is issued, and the review log in the pack says what was checked: the trial balance ties in every period, the balance sheet balances, cash flow reconciles to the movement in cash to the cent, each covenant ratio is recomputed from source.
  • The engine ships with its own verification suite of more than 1,800 assertions, including round-tripping a 42-month ledger through the database to the cent. The Ask layer is scored against a set of more than 100 real questions, and a misread question becomes a new case.

Access

  • The QuickBooks Online connection uses Intuit's accounting read scope. Plametrix cannot create, edit or delete anything in your file and cannot move money.
  • QuickBooks tokens are stored per company under row-level security and deleted the moment you disconnect, without ending the engagement.
  • Sign-in is by emailed link. Accounts are invited, never self-registered. No passwords exist to leak.
  • Row-level security is enforced at the database for every tenant table, including against the table owner. The application's own database role cannot bypass it, so an application-level fault does not by itself cross a tenant boundary.
  • The database's public data API is disabled. Nothing in a browser talks to the database.

Where data lives

  • Postgres hosted by Supabase on AWS in us-east-1 (Northern Virginia). Encrypted at rest and in transit.
  • Application code runs on Vercel in the United States (iad1). Your data passes through serverless functions in memory during a request and is not stored there.
  • Outbound email (sign-in links and, where you enable it, the scheduled pack) goes through Resend in the US region. The pack attachment passes through at send time; Resend is not a store of record.

What a language model sees

  • When you ask a question in plain English, the question text and the names of your accounts, metrics and locations are sent to Anthropic's API so the question can be turned into a calculation. Amounts, balances and statements are never sent.
  • Anthropic's commercial terms (effective June 17, 2025) state that Anthropic may not train models on customer content submitted through its services. Anthropic's published retention policy (updated July 1, 2026) deletes API inputs and outputs within 30 days.
  • If the model is unavailable, questions fall back to a built-in interpreter. Nothing about your statements, packs or covenant tests depends on a model being reachable.

Retention and deletion

  • Uploaded files are parsed in memory and never written to storage. What persists is the validated ledger you confirmed, not the file.
  • Packs are never stored. Each download or scheduled delivery is recomputed from the ledger at that moment, so there is no archive of stale documents to secure.
  • When an engagement ends, the workspace is deleted within 30 days of the owner's written request, sooner on request. Deletion removes the company's rows outright: ledger, schedules, approvals, delivery history and QuickBooks tokens.
  • Export is honoured before deletion on request: the ledger as loaded, in CSV, plus current statements. Deletion and export requests to info@plametrix.com are acknowledged within 2 business days and completed within 30 days.
  • Database backups are taken daily and the last seven days are retained. Backups are used only for disaster recovery. Deleted data leaves the backup window by expiry.

Incidents

  • Incident lead: Agon Grazhdani, info@plametrix.com. Reports from anyone, including clients and outside researchers, are acknowledged within one business day.
  • Affected clients are told without undue delay and no later than 72 hours after Plametrix concludes an incident touched their data: what is known, what was done, what remains uncertain.
  • Every incident ends with a short written record, timeline, cause, impact, fix and what changes, shared with the clients affected.

Certifications

Plametrix has not completed a SOC 2 audit. A Type I engagement is planned before broader rollout, and this page will say so the day it starts. Supabase, Vercel, Amazon Web Services, Resend, Intuit and Anthropic each maintain their own SOC 2 and related attestations, available from them on request. If your sponsor or lender has a security questionnaire, send it. Every answer on this page is the answer you will get there.

Subprocessors

Client financial data means the general ledger, trial balances, statements and the figures derived from them. Clients are notified before a new subprocessor touches client data.

ProviderWhat it doesSees client financial figuresRegion
Supabase, Inc.Database and sign-inYesAWS us-east-1
Vercel, Inc.Application hostingIn memory during a request onlyUS (iad1)
Amazon Web Services, Inc.Infrastructure under Supabase and ResendYes, under Supabaseus-east-1
Resend, Inc.Sign-in links and scheduled pack deliveryPack attachment at send timeUS
Intuit Inc.QuickBooks Online, for companies that connect itSource of the ledgerUS
Anthropic, PBCTurning a plain-English question into a calculationNo. Question text and account names onlyUS
GitHub, Inc.Source code hostingNoUS

Questions a questionnaire does not cover?

Ask them on a call, or email info@plametrix.com. The incident lead and the founder are the same person, and he answers.