Security & data handling

Your records, handled like evidence.

TriBalance processes some of the most sensitive books a firm keeps. This page states plainly how your data is handled, which controls are enforced by design, and which assurances we do not claim yet. When something on this page changes, the page changes.

What you upload, and what we never touch.

01 · Scope
In

Three CSV exports per close

Bank statement, trust journal, and client-ledger balances, uploaded by your operator for one close period at a time. Each file is retained privately, referenced by a content hash, and stays attributable to the exact close it supports.

Out

No bank credentials, ever

TriBalance never asks for online-banking logins and holds no connection to your bank. There is no code path that moves money, initiates a transfer, edits an account, or files anything with a court or regulator.

Controls enforced by design.

02 · By design

These are properties of how the product is built, not policies we ask you to trust. Access boundaries live in the database layer, records carry their own hashes, and the close stops rather than guesses.

  • 01Tenant isolation at the data layerEach firm's records are isolated with database-enforced row-level access rules, not just interface checks.
  • 02Role-scoped actionsOperator, reviewer, and attorney hold different permissions. Consequential writes run through controlled server-side procedures.
  • 03Private source retentionUploads live in private storage, referenced by content hash, with downloads through short-lived signed links only.
  • 04Approval bound to exact bytesAttorney sign-off attaches to the stored report version and its hash. Changing a source invalidates prior review and approval.
  • 05Append-only audit trail by designConsequential actions are recorded with actor and timestamp, designed so the record and the change succeed or fail together.
  • 06Fail closedMissing, conflicting, or uncertain input stops the close with a named reason and a safe recovery path.
  • 07Integer-cent arithmeticMoney is stored and computed as integer cents. Deterministic results, no floating point.

Transport and infrastructure

TLSAll connections to TriBalance are encrypted in transit.
HDRSStrict HTTP security headers on the public site. Independently checkable from your own browser today.
HOSTHosted on managed cloud infrastructure with platform-provided encryption of stored data.
LOGSFinancial values and source-document contents are excluded from application logs and marketing analytics by design.

What we do not claim yet.

03 · Open items
Open 1

No third-party security audit yet

An independent external security review is planned before open access. Until it is complete, we say so here rather than implying otherwise.

Planned
Open 2

No compliance attestation yet

TriBalance does not currently hold a SOC 2 or comparable attestation. We will not borrow trust from certificates we have not earned.

Roadmap
Open 3

Multi-factor authentication rollout

MFA and re-authentication for consequential actions, such as attorney approval, are on the near-term roadmap and planned as requirements before broader access.

In progress
Open 4

No direct bank connections

By design today. If a bank connection ships in the future, it ships with its own consent flow and data-quality controls, and this page will say exactly what it does.

By design
Open 5

General principles, not state rule packs

The engine applies general trust accounting principles. Reviewed, versioned state-specific rule packs are planned but not yet released. Your jurisdiction's specific requirements remain your responsibility.

Planned
Open 6

Supervised onboarding only

TriBalance is in a supervised design-partner phase. Onboarding is deliberately manual, and no firm's real trust data is accepted until our internal production verification gates for that firm's setup have passed.

Current phase

Your data, your exit.

04 · Ownership
01 · Ownership

You own your records

Trust account records, transaction data, and generated reports remain your property. We claim no ownership interest in your data.

02 · Export

Export any time

PDF reports and CSV exports are standard product features, not a support ticket. Your record stays portable and inspectable outside TriBalance.

03 · Deletion

Deletion on request

On written request we permanently delete your data within thirty days, subject to legal retention obligations. Details are in the Terms of Service.

Privacy questions: privacy@tribalance.io. Think you found a security issue? Tell us at hello@tribalance.io and we will take it seriously.

Plain statements, kept current.

Read how the reconciliation itself works, or see the legal boundaries in full. When our security posture changes, this page changes with it.