DualEntry maintains independent SOC 1 (Type I and Type II) and SOC 2 (Type I and Type II) attestations, regular third-party penetration testing, and continuous control monitoring. For current observation periods, trust service criteria, the subprocessor list, and security policies, visit the DualEntry Trust Center. DualEntry updates the Trust Center as attestations renew or change scope.
How DualEntry protects your data
DualEntry protects customer data with layered technical and operational controls across the platform.- Encryption in transit. All traffic to and from DualEntry runs over TLS 1.2 or higher.
- Encryption at rest. Customer data, backups, and sensitive fields (such as aggregator access tokens) are encrypted at rest.
- Tenant isolation. Every request is scoped to the authenticated organization; cross-tenant access is rejected at the API layer.
- Least-privilege access. Employee access to production systems is role-based, logged, and reviewed on a recurring cadence.
- Change management. All production changes flow through peer-reviewed pull requests, automated testing, and staged rollouts.
- Incident response. DualEntry maintains a documented incident response plan with defined severity levels, on-call rotations, and customer notification commitments.
How AI features use your data
DualEntry does not train or fine-tune AI models on your data. DualEntry’s AI features, including Accounting Intelligence, Bank Match AI, automated categorization, and anomaly detection, never fit or retrain a model on your organization’s records. Your corrections, confirmed matches, and conversations do not feed a training pipeline. When an AI feature runs, it works only with the records that task needs from your organization. Accounting Intelligence is further limited to what your own role can see, so it never reaches records you couldn’t open yourself. Some AI features do get more accurate as you use DualEntry, and that improvement comes from context rather than training. DualEntry looks up your own past records at the moment a suggestion is made and uses them as context:- Bank Match AI includes memo rules distilled from your confirmed matches. See how Bank Match AI reuses your past matches.
- Automated categorization reuses the most recent transaction you matched with the same description. See automated categorization.
- Anomaly detection includes your five most recent dismissal reasons as examples. See anomaly detection.
Single sign-on
DualEntry supports single sign-on (SSO) in two forms: Google and Microsoft sign-in for every user by default, and enterprise SSO through your organization’s own identity provider (IdP).Default sign-in options
Every user can sign in with Continue with Google, Continue with Microsoft, or an email and password. No setup is needed. The Google or Microsoft account’s email must match the address invited to DualEntry. See Sign in to DualEntry for the full sign-in steps.Supported identity providers
Enterprise SSO connects DualEntry to the identity provider your IT team already runs, so users sign in with their corporate credentials. DualEntry’s enterprise SSO is built on WorkOS and supports any identity provider that uses SAML 2.0 or OpenID Connect (OIDC), the two standard protocols for federated sign-in. Supported identity providers include:- Microsoft Entra ID (formerly Azure AD)
- Okta
- Google Workspace
- OneLogin
- JumpCloud
- PingFederate
- Microsoft AD FS
- Auth0
- CyberArk
- Shibboleth
- Duo
- VMware Workspace ONE
Enterprise SSO setup
DualEntry configures the enterprise SSO connection for your organization. There is no setup page in the app. Contact your DualEntry account team to start, and have your IT administrator available to complete the configuration in your identity provider. Each connection is scoped to one organization by its verified email domain, so a user’s identity provider assignment can’t cross into another organization’s connection. You can’t use a personal email domain, such as gmail.com or outlook.com, for an SSO connection. Invite each user in DualEntry before they first sign in with SSO. The invitation sets the user’s role, so the user signs in with the access you chose. See user roles and permissions for how roles work.Product controls that support your own compliance
DualEntry gives you the controls auditors expect to see under frameworks like SOC 1, SOC 2, and SOX:- Audit trail: immutable, append-only record of every data change, retained for 7 years by default.
- Approval workflows: enforce segregation of duties across bills, journal entries, and other transactions.
- User roles and permissions: granular, entity-scoped access control.
- Period locking: prevent changes to closed accounting periods.
- Banking connections: credentials collected in the aggregator’s hosted UI, never in DualEntry, with encrypted token storage and per-organization scoping.
- Data handling during a migration: where source credentials and exported data live during a migration, retention, and what disconnecting revokes.
Requesting reports and completing security reviews
The Trust Center is the fastest path to almost everything a security or vendor-management team asks for:- Visit trust.dualentry.com.
- Request access to gated documents (SOC reports, penetration test summary, policies). Access is granted after a clickthrough NDA.
- Download the artifact you need, or share the link with your security reviewer.