Skip to main content
TestimonialsContact Us

Your financial data, protected at every layer.

Your books stay inside your own accounting software, and every connection to them is locked down. Twelix is ISO 27001:2022 certified, SOC 2 Type II audited, and HIPAA and GDPR compliant.

Contact us

ISO certificates on request. SOC 2 Type II report shared under NDA.

Security status

Twelix Accounting

All controls active
  • ISO/IEC 27001:2022Information securityCertified
  • ISO 9001:2015Quality managementCertified
  • SOC 2 Type IIAICPA audit reportAudited
  • HIPAAHealth informationCompliant
  • GDPREU personal dataCompliant
  • MFA on every login
  • VPN only
  • Read-only access
  • 24-hour notice

Certified, audited and open to your review.

Outside auditors test these controls, not just our own checklists. Here is what each one means for your books, in plain words.

  • ISO 27001:2022 Certified Company

    ISO/IEC 27001:2022

    Certified

    An accredited auditor checked how we protect information, from logins to locked doors. Certified, not just aligned.

  • ISO 9001:2015 Certified Company

    ISO 9001:2015

    Certified

    Our work follows a documented quality process, so every monthly close is checked the same way each time.

  • AICPA SOC 2 Type II audited

    SOC 2 Type II

    Audited

    An independent CPA tested our controls over months, not a single day. The report is yours to read under NDA.

  • HIPAA compliant

    HIPAA

    Compliant

    If your books hold patient or insurance details, that information is handled under HIPAA privacy and security rules.

  • GDPR Compliant

    GDPR

    Compliant

    If you have customers in the European Union, their personal data gets the care GDPR requires.

Certified on the software your books live in

QuickBooks ProAdvisor Level 1 and 2, Xero Payroll certified and Gusto Payroll certified.

  • Intuit QuickBooks ProAdvisor Certified Level 1
  • Intuit QuickBooks ProAdvisor Certified Level 2
  • Xero Payroll Certified
  • Gusto Payroll Certified

Four layers between your books and everyone else.

Each layer covers a different risk, from the front door to the fine print. A gap in one is caught by the next.

  1. Physical security

    Protection that starts before anyone reaches a keyboard.

    • 24/7 CCTV across the whole facility
    • Biometric and access card entry
    • No personal phones at workstations
    • No USB storage devices
    • Screen privacy filters
    • Company-managed devices with remote wipe
    • No client data stored on local drives
  2. Network security

    Every connection is encrypted, filtered and recorded.

    • Company-managed VPN, required for all work
    • Open internet blocked at network level during work hours
    • Firewall allows approved platforms only
    • Every connection monitored and logged
    • Network segmented for each client
  3. Access controls

    The right person, at the right level, for one account only.

    • MFA required on every platform
    • No single-factor logins
    • Role-based access set for each client account
    • Formal steps to grant and remove access
    • Automatic session timeouts
    • Passwords kept in a managed password tool
  4. Legal and contractual

    Each control is backed by a signed agreement.

    • NDA signed by everyone before day one
    • Confidentiality terms written for your account
    • Data handling documented before work starts
    • Encrypted file transfer only
    • No personal cloud storage, unprotected email or messaging apps

How your data moves, and where it never goes.

The work happens inside your accounting software. Nothing is copied to a personal device, inbox or drive along the way.

Your accounting software connects through an encrypted company VPN, with MFA sign-in, to a secure workstation at our operations center. Open internet, USB drives, personal phones and personal file apps are blocked. Completed work stays in your own file.

Your accounting software

QuickBooks, Xero or the platform you already use, in your name.

  • Your login rules
  • Your audit log

Encrypted company VPN

Every session runs through our managed VPN and firewall.

  • Approved platforms only
  • Logged

Secure workstation

A company-managed device inside our monitored operations center.

  • MFA
  • CCTV
  • No USB

Blocked at the workstation

  • Open internet during work hours
  • USB drives and local downloads
  • Personal phones at the desk
  • Personal cloud, email and chat apps for files

Finished work stays in your file

Every entry and reconciliation is saved in your own software. There is nothing to download and nothing to send back.

Your file stays in your name, under your control.

Twelix is a service, not another system to trust with a copy of your books. We work in the tools you already own, with the access you choose.

  • The work happens in your software

    We log in to QuickBooks, Xero or the platform you already use. No second copy of your books sits on our side.

  • The file stays in your name

    You own the subscription and the data. We never move your books into an account we control.

  • Read-only wherever possible

    When your platform offers a read-only role that fits the work, that is the role we ask for.

  • You set access and can revoke it

    You choose what we can see and change. Remove our user at any time from your own settings.

  • Your bank stays read-only

    Bank and card feeds are read-only and used to reconcile. If we run payroll, it runs in your own payroll account.

  • Every close gets a second review

    A second person checks each monthly close before it reaches you, so mistakes are caught early.

Users and access

An example of what you see in your own settings

Twelix AccountingAccountant user, invited by youActive
  • Company file ownerYou
  • Access levelSet by you
  • Bank and card feedsRead-only
  • Payments and transfersNo access
  • Changes we makeIn your audit log
You can remove this user at any time.

If something goes wrong, you know within 24 hours.

Good security plans for the bad day and for the last day. Here is what we commit to in writing, before any work starts.

Incident response

  1. 1

    Immediately

    We contain it

    Containment starts the moment an incident is found. Affected access is shut off while we investigate.

  2. 2

    Within 24 hours

    We tell you

    You hear from us within 24 hours of a verified incident, with what happened and what we have done so far.

  3. 3

    In writing

    We report the root cause

    You get a written post-incident report covering the root cause and the steps taken to stop it happening again.

When the work ends

  • Our access to your software is removed
  • Data on our systems is securely deleted or returned, your choice
  • Written proof of deletion on request

Review us before you sign

Security questionnaires, due diligence reviews and IT assessments are welcome. We answer in writing and provide our control documentation.

Security questions, answered plainly.

  1. Twelix is certified to ISO/IEC 27001:2022, not just aligned with it. An accredited certification body audited our controls independently. Aligned would mean following the standard with no outside audit. We also hold ISO 9001:2015, and both certificates are available on request.

  2. Yes, Twelix is HIPAA compliant. When your books include patient or insurance details, that information is handled under the HIPAA privacy and security rules. This matters most for medical, dental and therapy practices. See how we keep books for healthcare practices.

  3. Yes, Twelix is SOC 2 Type II audited under AICPA standards. A Type II audit tests whether our controls worked over a period of months, not only on a single day. We share the report on request under NDA, so your IT or compliance lead can read it in full.

  4. Only the people who work on your account can see your books, at the access level you approve. Access is set by role, protected by MFA and logged. Everyone with access has signed an NDA, and we remove access as soon as it is no longer needed.

  1. The work is done at our operations center in India, run by our parent company, NetBounce Global LLC. The facility is CCTV monitored with biometric entry, and every device is company managed. Your books never leave your own accounting software.

  2. No, Twelix cannot move money out of your bank. Bank and card connections are read-only and are used only to reconcile your accounts. If we run payroll for you, it runs inside your own payroll account, under your company's name and on the schedule you set.

  3. You keep your books, because they were always in your software and in your name. We remove our access, then securely delete or return any data on our systems, whichever you prefer. Ask, and we send written proof that deletion is complete.

  4. Yes, and we encourage it. Send your security questionnaire, due diligence checklist or IT assessment before you sign anything. We answer in writing and share our control documentation, ISO certificates and SOC 2 Type II report under NDA.

Outsource the books, keep the control.

Book a 30-minute call and bring every security question you have. Prefer to start in writing? Send us your questionnaire first.

Talk to us first

ISO 27001:2022 certified · SOC 2 Type II audited · HIPAA compliant