Your bank credentials never touch our servers
Bank connections run through Plaid, the same connectivity service used by most major financial apps. When you link a bank, your online banking credentials go directly to Plaid. Bizdivers never sees them and never stores them. You can disconnect any bank at any time from the Banking page, and if you prefer not to link online banking at all, you can import transactions from CSV files instead.
Two-factor authentication from day one
Every account owner sets up two-factor authentication during signup, before anything else. It's the first step of onboarding, not an optional setting buried in a menu. You can use an authenticator app or codes sent by text message, and teammates enroll when they accept their invitation.
Access control built for separation of duties
Roles run from read-only Viewer through Clerk, Approver, and Manager to Admin, and they're enforced in the product's workflows, not just its menus. Approval thresholds route larger amounts to more senior roles, and the control tests flag any entry where the preparer and the approver are the same person. Giving your bookkeeper access doesn't mean giving them the keys to everything.
Every action on the record
Sign-ins, settings changes, approvals, payments, journal entry activity: every meaningful action is written to an audit log with who did it, when, from which IP, and a before-and-after diff of what changed. The log is part of the product, visible under Accounting, not a support ticket away.
How your data is handled
All traffic between your browser and Bizdivers is encrypted in transit with TLS. Data lives in a managed database that is encrypted at rest by our infrastructure provider. Sensitive values like taxpayer identification numbers are stored masked in the interface. Your data is never sold, and it's yours to take: the ledger, trial balance, and assessment views export to CSV, and audit packets download as PDFs.
Deleting your data
You can permanently delete your account and personal data at any time. Some records are retained where accounting and tax law requires it; the specifics are on the account deletion page and in the privacy policy.
Questions?
Write to contact@bizdivers.com and a human will answer. If you believe you've found a security vulnerability, please use the same address and we'll prioritize it.
When your accountant needs access
Audit Connect, our portal for accounting firms, runs on a separate sign-in realm with its own credentials: a firm login cannot open a client door, and a client login cannot open a firm one. The separation is enforced in the authentication layer, not in a settings page. A firm sees your books only after you grant access explicitly, the access is read-only by construction, and every single read the firm makes is written to a log you can inspect. You can revoke a grant at any time. More on Audit Connect.