Zerqis
Security

Built for work that has to be auditable.

Accounting software carries other people's financial records. These are the controls Zerqis is built on, and an honest account of where the product currently stands.

Controls in the product

How access, isolation and accountability work inside Zerqis today.

Tenant isolation

Every query is scoped to the organization resolved on the server. Nothing the browser sends is trusted as an organization identifier.

Role-based access

Preparers, reviewers and managers see the work that belongs to them, with approval reserved for the reviewer role.

Audit trail

Categorization changes, approvals and client questions are recorded with the actor and the reason behind them.

Explainable suggestions

Every AI suggestion carries the history and rules it was drawn from, so a reviewer can audit the reasoning rather than trust a score.

Your data stays yours

Client transaction data is used to serve your firm. It is not pooled across customers to train a shared model.

Human approval

Zerqis does not post an accounting decision on its own. A person signs off before a close completes.

Where we actually are

Certifications we have not completed yet

Zerqis is an early-stage product. We would rather say this plainly than imply a compliance posture we have not earned.

  • No SOC 2 report has been issued. An audit is planned, not completed.
  • No ISO 27001 certification is in place today.
  • Penetration testing by a third party has not yet been performed.
  • We will publish evidence when it exists rather than badges before it does.

If your firm has a security review process, contact us and we will answer your questionnaire with the current state of the product.

Reviewing Zerqis for your firm?

We are happy to walk your team through the data model, the access controls and the parts still in progress.