Skip to content
Accountive
ComplyLiteStart free
Legal

Data protection and security

Last updated 28/09/2026 ยท Applies to www.accountive.ae, Accountive Comply and Accountive Lite

Accounting records are some of the most sensitive information a business has. This page explains how each of our products protects them, where they are stored, who at Accountive can see them, what you can do on your side, and what is not switched on yet. What personal data we collect, and why, is in our privacy policy. The terms for using our products are in our Terms and Conditions.

At a glance

ComplyLite
Where data is storedHostinger servers in Mumbai, IndiaHostinger servers in Mumbai, India
ConnectionsHTTPS onlyHTTPS only
Account passwordsOne-way hash (Argon2id, or bcrypt where the server does not support it), checked against known breachesOne-way hash (scrypt)
Two-step sign-inAvailable to every user; firms on the Practice and Firm plans can require itOptional for every user, with an authenticator app
Uploaded documentsEncrypted at restStored in the database, not separately encrypted
Separation between customersEvery read limited to your firm's workspaceEach customer's books kept separately
BackupsEvery night, encrypted, newest 14 keptDaily snapshot of each account's records, newest 5 kept; uploaded documents not included
Accountive staff accessOperator console that needs an authenticator app; changes it makes recorded in the firm's activity logA few platform admins; exports, restores, repairs, suspensions and resets recorded

Accountive Comply

  • One firm cannot reach another. Every record is tagged with the workspace of the firm that owns it. The application limits every read to the workspace of the person signed in, taken from their session and never from the request, and database checks refuse any write to another firm's client records. Automated tests check that one firm cannot reach another firm's data.
  • Passwords. Staff passwords are stored only as one-way hashes, using Argon2id, or bcrypt where the server does not support Argon2id. New passwords must be at least 10 characters and are checked against known data breaches using the haveibeenpwned.com range service: only the first 5 characters of a SHA-1 hash of the password leave our server. Repeated wrong passwords lock sign-in for a short time.
  • Email confirmation. New Comply sign-ups are asked to confirm their email address; until they do, Comply sends nothing to their clients.
  • Two-step sign-in. Any Comply user can turn on two-step sign-in with an authenticator app, and gets one-time recovery codes in case they lose their phone. Firms on the Practice and Firm plans can require it for everyone on the team.
  • Sessions. The sign-in cookie holds a random code that scripts on the page cannot read. We store only a hash of it, so a copy of our database could not be used to sign in as you.
  • Encryption at rest. Uploaded documents and support screenshots are encrypted with XChaCha20-Poly1305 (libsodium). Client-portal passwords your firm saves are encrypted too. The key is held on our server, so this protects the stored files if they are copied on their own; it cannot protect them from someone who takes over the whole server. Other records, such as client details and imported bank statement lines, are stored in the database without separate application-level encryption.
  • Backups. A full backup is taken every night and encrypted, and the newest 14 are kept. They are stored on the same server as the live data, so we recommend you also keep your own exports.
  • Activity log. Comply keeps a log of who changed what and when, so your firm has an audit trail.
  • Our access. Our operator console requires an authenticator app (two-step sign-in) and records the changes operators make to a firm's workspace in that firm's activity log. We use it only to support customers.

Accountive Lite

  • Your books are kept separate. Each customer's books are stored separately, and every request is tied to the account that is signed in. In the app, uploaded documents can only be opened by people signed in to the company they were uploaded to.
  • Passwords. Stored only as one-way hashes, using scrypt. Passwords must be at least 10 characters. Changing your password signs out your other sessions.
  • Two-step sign-in. Any Lite user can turn on two-step sign-in with an authenticator app. Once it is on, signing in also asks for a 6-digit code, and turning it off needs both your password and a current code.
  • Password reset by email. A reset link works once and expires after 60 minutes, and the answer never reveals whether an email address has an account. Saving a new password signs you out on every device, and two-step sign-in still applies. This works only once email sending is switched on for Lite.
  • Your accountant and team. The owner chooses which areas of the books each invited person can open, such as Sales, Banking or Tax, and the server enforces that choice. Only the owner can invite people or change their access.
  • Switching from another system. If you choose to connect Zoho Books, Xero or QuickBooks Online to move your books into Lite, Lite only reads from that service. QuickBooks asks for full accounting access because it offers no read-only option, but Lite only reads from it. The access token is stored encrypted and is deleted when you disconnect; Lite disconnects automatically when the switch finishes. You can import export files instead.
  • Sessions. As in Comply, the sign-in cookie holds a random code that scripts on the page cannot read, and we store only a hash of it. It lasts up to 30 days, or until you sign out.
  • Documents. PDFs and images you upload, up to 10 MB each, are stored in the Lite database. They are not separately encrypted by the application.
  • Daily snapshots. An automatic snapshot of each account is taken every day and the newest 5 are kept, in the same database, so your books' records can be restored if something goes wrong. Snapshots do not include uploaded documents.
  • Our access. A small number of Accountive platform administrators can export, restore, repair, suspend or reset an account, only to support customers. These actions are recorded in an audit log. If we reset your password, all your sessions are signed out and you receive a temporary password to change.
  • Browser protections. The app sends strict security headers, including a content security policy that only lets its own scripts run, and it refuses changes sent from other websites.

This website

www.accountive.ae is a set of static pages plus a checkout at www.accountive.ae/start/. It has no sign-in, no cookies and no analytics. It is served only over HTTPS and tells browsers to always use HTTPS, other sites cannot embed it in a frame, and a content security policy only lets our own reviewed scripts run. The one outside service the pages use is Google Fonts.

The checkout is the only part of the website that sends data. It sends your order details only to our own server, which stores them in a database on our Hostinger hosting. It accepts orders only from our own website, limits repeated attempts, and works out prices on the server, never from the browser. Card payments, once switched on, happen on Stripe's own payment page, so card details never reach our server. What the checkout collects is listed in our privacy policy.

Where your data is stored

  • Servers and databases: Hostinger, in Mumbai, India, for this website, Comply and Lite. Your data is therefore stored outside the UAE.
  • Domain and DNS: accountive.ae is registered, and its DNS managed, at AEserver in the UAE.
  • Email: Comply's emails are delivered by Resend in the United States. Our @accountive.ae mailboxes are hosted by Hostinger Email, and checkout receipts are sent through them. Lite sends email only once email sending is switched on for it, through Resend or our Hostinger mailboxes.
  • Server access: besides the admin consoles, the people who operate our servers can reach the databases and stored files directly through our hosting account. This is used only to run, repair or restore the service, and it is not recorded by the apps.

The full list of providers, what each one does and where, is in the privacy policy.

Who is responsible for what

When an accounting firm puts its clients' data into Comply, the firm is the controller: it decides what to upload and how that data is used. Accountive is the processor: we handle that data only on the firm's instructions, to run the service.

In Lite, you decide what goes into your books, including any details of your customers and suppliers, and we process it only to run the service for you.

For data about you as our customer, such as your account and billing details, we are the controller, as our privacy policy explains. Our Terms and Conditions set out the rest of what we agree with you, including cancellation and what happens to your data afterwards.

What you can do on your side

  • Use a strong, unique password of at least 10 characters that you do not use anywhere else. A password manager makes this easy.
  • Turn on two-step sign-in in Comply and in Lite. In Comply, require it for your whole team if your plan allows, and keep your recovery codes somewhere safe, away from your phone.
  • Do not share logins. Give each person their own account, and remove people who leave your firm straight away.
  • Download exports regularly and keep your own copy. Comply owners and admins can download the workspace's records (Excel or JSON) at any time; uploaded files are downloaded from each request, and saved portal passwords are not included.
  • Upload only what you need. Neither product needs health or biometric data, so please do not upload it.
  • Sign out on shared computers, and keep your device and browser up to date.
  • Act quickly if you think someone else has used your account: change your password and email security@accountive.ae.

Reporting a security problem

If you believe you have found a vulnerability in this website, Comply or Lite, email security@accountive.ae. The same address is published in our security.txt file. You can write in English or Arabic.

  • Tell us what you found, where, and the steps to reproduce it.
  • Do not access, change or delete other people's data beyond the minimum needed to show the problem, and do not run tests that slow down or break the service.
  • Give us a reasonable chance to fix it before you publish anything.

We will acknowledge your report within one working day and keep you posted until it is closed. We will not take legal action against anyone who reports a genuine issue in good faith and gives us a reasonable chance to fix it before publishing.

What is not switched on yet

  • Lite does not confirm email addresses at sign-up yet.
  • Lite documents are not encrypted by the application, as Comply's are. They are stored in the Lite database.
  • Lite snapshots do not cover uploaded documents. Keep your own copies of the documents you upload.
  • Lite's password reset by email works only once email sending is switched on for Lite. If the sign-in page says reset by email is not switched on yet, email support@accountive.ae from your account's email address.
  • Backups are not kept at a separate location. Comply's backups are on the same server as the live data, and Lite's snapshots are in the same database. Keep your own exports as well.
  • Card payments are built into Comply and our checkout but not switched on. Until they are, plans are activated with a promo code.
  • Automatic WhatsApp messages from a WhatsApp Business number are built into Comply but not switched on. The "Send on WhatsApp" button only opens WhatsApp on your own phone or computer with the message ready; we do not send it.
  • Viewing is not recorded. Comply's operator console records the changes operators make to a firm's workspace, but not when they only look at it.
  • Checkout orders are not deleted automatically yet. They are kept with our billing records, as our privacy policy explains.
  • We hold no ISO 27001 or SOC 2 certificate. We would rather explain exactly how the system works than point at a badge.

We will update this page as these change.

Contact

SCORP Nexus, Dubai, United Arab Emirates

Security problems: security@accountive.ae
Privacy questions and requests: privacy@accountive.ae

Accountive

Accounting and compliance software made in Dubai. Operated by SCORP Nexus, Dubai, UAE.

Products

Accountive ComplyAccountive Lite

For accounting firms

Practice managementKPO teamsCorporate TaxVATAML

Sign in

Comply sign inLite sign in

Company

Privacy policyData protectionRefund policyTerms and Conditions