
ISO/IEC 27001:2022
Certified
An accredited auditor checked how we protect information, from logins to locked doors. Certified, not just aligned.
Your books stay inside your own accounting software, and every connection to them is locked down. Twelix is ISO 27001:2022 certified, SOC 2 Type II audited, and HIPAA and GDPR compliant.
ISO certificates on request. SOC 2 Type II report shared under NDA.
Security status
Twelix Accounting
ISO/IEC 27001:2022Information securityCertified
ISO 9001:2015Quality managementCertified
SOC 2 Type IIAICPA audit reportAudited
HIPAAHealth informationCompliant
GDPREU personal dataCompliantOutside auditors test these controls, not just our own checklists. Here is what each one means for your books, in plain words.

Certified
An accredited auditor checked how we protect information, from logins to locked doors. Certified, not just aligned.

Certified
Our work follows a documented quality process, so every monthly close is checked the same way each time.

Audited
An independent CPA tested our controls over months, not a single day. The report is yours to read under NDA.

Compliant
If your books hold patient or insurance details, that information is handled under HIPAA privacy and security rules.

Compliant
If you have customers in the European Union, their personal data gets the care GDPR requires.
Certified on the software your books live in
QuickBooks ProAdvisor Level 1 and 2, Xero Payroll certified and Gusto Payroll certified.




Each layer covers a different risk, from the front door to the fine print. A gap in one is caught by the next.
Protection that starts before anyone reaches a keyboard.
Every connection is encrypted, filtered and recorded.
The right person, at the right level, for one account only.
Each control is backed by a signed agreement.
The work happens inside your accounting software. Nothing is copied to a personal device, inbox or drive along the way.
Your accounting software connects through an encrypted company VPN, with MFA sign-in, to a secure workstation at our operations center. Open internet, USB drives, personal phones and personal file apps are blocked. Completed work stays in your own file.
QuickBooks, Xero or the platform you already use, in your name.
Every session runs through our managed VPN and firewall.
A company-managed device inside our monitored operations center.
Blocked at the workstation
Finished work stays in your file
Every entry and reconciliation is saved in your own software. There is nothing to download and nothing to send back.
Twelix is a service, not another system to trust with a copy of your books. We work in the tools you already own, with the access you choose.
We log in to QuickBooks, Xero or the platform you already use. No second copy of your books sits on our side.
You own the subscription and the data. We never move your books into an account we control.
When your platform offers a read-only role that fits the work, that is the role we ask for.
You choose what we can see and change. Remove our user at any time from your own settings.
Bank and card feeds are read-only and used to reconcile. If we run payroll, it runs in your own payroll account.
A second person checks each monthly close before it reaches you, so mistakes are caught early.
Users and access
An example of what you see in your own settings
Good security plans for the bad day and for the last day. Here is what we commit to in writing, before any work starts.
Immediately
We contain it
Containment starts the moment an incident is found. Affected access is shut off while we investigate.
Within 24 hours
We tell you
You hear from us within 24 hours of a verified incident, with what happened and what we have done so far.
In writing
We report the root cause
You get a written post-incident report covering the root cause and the steps taken to stop it happening again.
Security questionnaires, due diligence reviews and IT assessments are welcome. We answer in writing and provide our control documentation.
Twelix is certified to ISO/IEC 27001:2022, not just aligned with it. An accredited certification body audited our controls independently. Aligned would mean following the standard with no outside audit. We also hold ISO 9001:2015, and both certificates are available on request.
Yes, Twelix is HIPAA compliant. When your books include patient or insurance details, that information is handled under the HIPAA privacy and security rules. This matters most for medical, dental and therapy practices. See how we keep books for healthcare practices.
Yes, Twelix is SOC 2 Type II audited under AICPA standards. A Type II audit tests whether our controls worked over a period of months, not only on a single day. We share the report on request under NDA, so your IT or compliance lead can read it in full.
Only the people who work on your account can see your books, at the access level you approve. Access is set by role, protected by MFA and logged. Everyone with access has signed an NDA, and we remove access as soon as it is no longer needed.
The work is done at our operations center in India, run by our parent company, NetBounce Global LLC. The facility is CCTV monitored with biometric entry, and every device is company managed. Your books never leave your own accounting software.
No, Twelix cannot move money out of your bank. Bank and card connections are read-only and are used only to reconcile your accounts. If we run payroll for you, it runs inside your own payroll account, under your company's name and on the schedule you set.
You keep your books, because they were always in your software and in your name. We remove our access, then securely delete or return any data on our systems, whichever you prefer. Ask, and we send written proof that deletion is complete.
Yes, and we encourage it. Send your security questionnaire, due diligence checklist or IT assessment before you sign anything. We answer in writing and share our control documentation, ISO certificates and SOC 2 Type II report under NDA.
Book a 30-minute call and bring every security question you have. Prefer to start in writing? Send us your questionnaire first.
ISO 27001:2022 certified · SOC 2 Type II audited · HIPAA compliant