ClarifyBooks

Trust and access

How ClarifyBooks handles client access and QuickBooks data

ClarifyBooks keeps the trust boundary narrow: read from QBO, collect client clarification through controlled links, review before export, and keep final posting in the existing bookkeeping workflow.

Read-only QuickBooks Online import

ClarifyBooks can preview and import QBO transaction data for review. It does not update QBO transactions, create QBO records, attach receipts to QBO, or write categories back.

Secure client links

Client response links use unguessable random tokens and stored token hashes. Clients do not need QuickBooks access to answer selected transaction questions.

Review before exporting

Answers and receipts land in the review queue. The bookkeeper decides what is ready, what needs follow-up, and when to export CSV.

Data storage and retention

ClarifyBooks stores app records in the configured database and receipt files in the configured upload storage. Exportability is available through CSV. Automated retention is not advertised as a public feature.

Access controls

Authenticated app access is firm-scoped. Owner, admin, and staff roles keep settings and team management narrower than normal workflow access.

Backups and incident handling

Backup, rollback, monitoring, and incident procedures are documented for private beta operation. This page does not claim external audit certification or completed production restore rehearsal beyond recorded proof.

What ClarifyBooks does not do

ClarifyBooks does not write back to QuickBooks, does not auto-categorize with AI, does not replace practice management, and does not require clients to log into QuickBooks.

Plain facts this public surface can state

QBO read-onlyNo write-backNo AI categorizationEncrypted QBO tokens when QBO is configuredFirm-scoped accessSecure public linksReceipt upload validationStripe-hosted billingNo direct card collectionCSV exportabilityPrivate beta boundaries

ClarifyBooks does not claim SOC 2, ISO 27001, HIPAA, bank-grade security, enterprise-grade security, audit-proof workflows, customer traction, or public launch status.