Your records, handled like evidence.
TriBalance processes some of the most sensitive books a firm keeps. This page states plainly how your data is handled, which controls are enforced by design, and which assurances we do not claim yet. When something on this page changes, the page changes.
What you upload, and what we never touch.
Three CSV exports per close
Bank statement, trust journal, and client-ledger balances, uploaded by your operator for one close period at a time. Each file is retained privately, referenced by a content hash, and stays attributable to the exact close it supports.
No bank credentials, ever
TriBalance never asks for online-banking logins and holds no connection to your bank. There is no code path that moves money, initiates a transfer, edits an account, or files anything with a court or regulator.
Controls enforced by design.
These are properties of how the product is built, not policies we ask you to trust. Access boundaries live in the database layer, records carry their own hashes, and the close stops rather than guesses.
- 01Tenant isolation at the data layerEach firm's records are isolated with database-enforced row-level access rules, not just interface checks.
- 02Role-scoped actionsOperator, reviewer, and attorney hold different permissions. Consequential writes run through controlled server-side procedures.
- 03Private source retentionUploads live in private storage, referenced by content hash, with downloads through short-lived signed links only.
- 04Approval bound to exact bytesAttorney sign-off attaches to the stored report version and its hash. Changing a source invalidates prior review and approval.
- 05Append-only audit trail by designConsequential actions are recorded with actor and timestamp, designed so the record and the change succeed or fail together.
- 06Fail closedMissing, conflicting, or uncertain input stops the close with a named reason and a safe recovery path.
- 07Integer-cent arithmeticMoney is stored and computed as integer cents. Deterministic results, no floating point.
Transport and infrastructure
What we do not claim yet.
No third-party security audit yet
An independent external security review is planned before open access. Until it is complete, we say so here rather than implying otherwise.
No compliance attestation yet
TriBalance does not currently hold a SOC 2 or comparable attestation. We will not borrow trust from certificates we have not earned.
Multi-factor authentication rollout
MFA and re-authentication for consequential actions, such as attorney approval, are on the near-term roadmap and planned as requirements before broader access.
No direct bank connections
By design today. If a bank connection ships in the future, it ships with its own consent flow and data-quality controls, and this page will say exactly what it does.
General principles, not state rule packs
The engine applies general trust accounting principles. Reviewed, versioned state-specific rule packs are planned but not yet released. Your jurisdiction's specific requirements remain your responsibility.
Supervised onboarding only
TriBalance is in a supervised design-partner phase. Onboarding is deliberately manual, and no firm's real trust data is accepted until our internal production verification gates for that firm's setup have passed.
Your data, your exit.
You own your records
Trust account records, transaction data, and generated reports remain your property. We claim no ownership interest in your data.
Export any time
PDF reports and CSV exports are standard product features, not a support ticket. Your record stays portable and inspectable outside TriBalance.
Deletion on request
On written request we permanently delete your data within thirty days, subject to legal retention obligations. Details are in the Terms of Service.
Privacy questions: privacy@tribalance.io. Think you found a security issue? Tell us at hello@tribalance.io and we will take it seriously.
Plain statements, kept current.
Read how the reconciliation itself works, or see the legal boundaries in full. When our security posture changes, this page changes with it.
Prefer the fine print? Read the legal disclaimer.