Reconciliation touches sensitive financial data. Here's how QRecon protects it.
Last updated: September 2026
Data in transit between your browser, QRecon, and connected providers (Stripe, PayPal, QuickBooks) is encrypted using TLS. Data at rest, including account and reconciliation records, is encrypted in our database and storage layers.
When you connect Stripe, PayPal, or QuickBooks, QRecon requests the narrowest OAuth scope each provider offers for reconciliation - read access to payouts, transactions, and ledger entries. QRecon cannot initiate a payment, transfer, or withdrawal from any connected account.
Internal access to production systems and customer data is limited to the personnel who need it to operate and support the Service, and is logged. Multi-factor authentication is required for access to critical infrastructure.
We follow secure development practices, including code review before deployment and dependency monitoring for known vulnerabilities. We aim to align our practices with recognized frameworks such as the OWASP Top 10 and industry-standard cloud security guidance.
QRecon runs on reputable cloud infrastructure with built-in redundancy, automated backups, and monitoring for availability and abnormal activity.
We maintain a process for identifying, containing, and remediating security incidents. If an incident affects your data, we will notify you without undue delay and in accordance with applicable law.
If you believe you've found a security vulnerability in QRecon, please report it to hello@qrecon.ai. Please give us a reasonable amount of time to investigate and address the issue before disclosing it publicly. We do not take legal action against good-faith, responsible security research.
This page is provided as a general template for informational purposes and does not constitute legal advice or a certification of compliance with any specific security standard.