Trust and security

Protection for sensitive finance data, backed by audited controls.

At xpna, we recognise the responsibility that comes with being entrusted with customer financial data. xpna complies with relevant legislation relating to security and privacy of customer data.

SOC 2 Type II

Controls that operate effectively over time.

xpna has achieved SOC 2 Type II certification, demonstrating that our security controls are not only well-designed but operate effectively over time.

The platform behind your reports is independently audited for rigorous control operations including access management, change management, incident response, monitoring and data handling.

AICPA SOC 2

You own your data

All intellectual property rights and ownership of data are retained by the customer. You control access to your data and can remove an organisation from your xpna account whenever you choose. When you do so, xpna will also revoke related access tokens.

Hosting and physical security

xpna operates entirely within the Microsoft Azure cloud, a platform known for robust security and privacy features. All data is stored in Azure data centres located in Australia.

Encryption

All data is encrypted at rest using 256-bit AES encryption. All communication from a user machine to our servers is over HTTPS and protected with SSL 256-bit AES encryption.

Data protection and backup

xpna backs up and encrypts data with 256-bit AES encryption, storing backups securely in a secondary data centre. Backups can be as frequent as every 10 minutes so services can be restored from an alternate location if needed.

User access and account security

As a certified Microsoft Excel add-in, xpna integrates with the Microsoft account system and leverages Microsoft security protocols. xpna does not have, and will never ask for, your password. Multi-factor authentication is recommended for all users.

Workspaces

An xpna workspace is a collection of data and associated metadata. Businesses typically maintain one workspace for their data, while accountants, bookkeepers and fractional CFOs usually maintain separate workspaces for each client to ensure segregation.

Vulnerability disclosure

xpna maintains a vulnerability disclosure policy so security researchers can responsibly share findings with us. If you think you have found a potential vulnerability, review the policy and submit findings to security@xpna.co.

Secure finance workflows

Move faster without compromising protection.

Plan, consolidate, report and forecast confidently on a platform designed for finance teams and verified by audit.