Skip to main content
DualEntry is built and operated to meet the security expectations of finance and accounting teams. This page summarizes how the platform protects your data; for compliance specifics, the DualEntry Trust Center is the source of truth.
DualEntry maintains independent SOC 1 (Type I and Type II) and SOC 2 (Type I and Type II) attestations, regular third-party penetration testing, and continuous control monitoring. For current observation periods, trust service criteria, the subprocessor list, and security policies, visit the DualEntry Trust Center. DualEntry updates the Trust Center as attestations renew or change scope.

How DualEntry protects your data

DualEntry protects customer data with layered technical and operational controls across the platform.
  • Encryption in transit. All traffic to and from DualEntry runs over TLS 1.2 or higher.
  • Encryption at rest. Customer data, backups, and sensitive fields (such as aggregator access tokens) are encrypted at rest.
  • Tenant isolation. Every request is scoped to the authenticated organization; cross-tenant access is rejected at the API layer.
  • Least-privilege access. Employee access to production systems is role-based, logged, and reviewed on a recurring cadence.
  • Change management. All production changes flow through peer-reviewed pull requests, automated testing, and staged rollouts.
  • Incident response. DualEntry maintains a documented incident response plan with defined severity levels, on-call rotations, and customer notification commitments.
These controls apply uniformly rather than per feature, which matters when a reviewer asks about a specific workflow. A migration and a bank connection are both covered by the same encryption, isolation, and access policies as the rest of the platform. The answer to “is this part in scope” is the same for each.

How AI features use your data

DualEntry does not train or fine-tune AI models on your data. DualEntry’s AI features, including Accounting Intelligence, Bank Match AI, automated categorization, and anomaly detection, never fit or retrain a model on your organization’s records. Your corrections, confirmed matches, and conversations do not feed a training pipeline. When an AI feature runs, it works only with the records that task needs from your organization. Accounting Intelligence is further limited to what your own role can see, so it never reaches records you couldn’t open yourself. Some AI features do get more accurate as you use DualEntry, and that improvement comes from context rather than training. DualEntry looks up your own past records at the moment a suggestion is made and uses them as context: Because this context is read from your organization’s own records each time, it changes when your records change and is never shared with another organization. The AI model providers DualEntry uses are listed on the Trust Center subprocessor list.

Single sign-on

DualEntry supports single sign-on (SSO) in two forms: Google and Microsoft sign-in for every user by default, and enterprise SSO through your organization’s own identity provider (IdP).

Default sign-in options

Every user can sign in with Continue with Google, Continue with Microsoft, or an email and password. No setup is needed. The Google or Microsoft account’s email must match the address invited to DualEntry. See Sign in to DualEntry for the full sign-in steps.

Supported identity providers

Enterprise SSO connects DualEntry to the identity provider your IT team already runs, so users sign in with their corporate credentials. DualEntry’s enterprise SSO is built on WorkOS and supports any identity provider that uses SAML 2.0 or OpenID Connect (OIDC), the two standard protocols for federated sign-in. Supported identity providers include:
  • Microsoft Entra ID (formerly Azure AD)
  • Okta
  • Google Workspace
  • OneLogin
  • JumpCloud
  • PingFederate
  • Microsoft AD FS
  • Auth0
  • CyberArk
  • Shibboleth
  • Duo
  • VMware Workspace ONE
You can also use any identity provider on WorkOS’s list of supported providers.

Enterprise SSO setup

DualEntry configures the enterprise SSO connection for your organization. There is no setup page in the app. Contact your DualEntry account team to start, and have your IT administrator available to complete the configuration in your identity provider. Each connection is scoped to one organization by its verified email domain, so a user’s identity provider assignment can’t cross into another organization’s connection. You can’t use a personal email domain, such as gmail.com or outlook.com, for an SSO connection. Invite each user in DualEntry before they first sign in with SSO. The invitation sets the user’s role, so the user signs in with the access you chose. See user roles and permissions for how roles work.

Product controls that support your own compliance

DualEntry gives you the controls auditors expect to see under frameworks like SOC 1, SOC 2, and SOX:
  • Audit trail: immutable, append-only record of every data change, retained for 7 years by default.
  • Approval workflows: enforce segregation of duties across bills, journal entries, and other transactions.
  • User roles and permissions: granular, entity-scoped access control.
  • Period locking: prevent changes to closed accounting periods.
  • Banking connections: credentials collected in the aggregator’s hosted UI, never in DualEntry, with encrypted token storage and per-organization scoping.
  • Data handling during a migration: where source credentials and exported data live during a migration, retention, and what disconnecting revokes.
These are configuration rather than defaults, so an auditor testing them will ask what you turned on. Segregation of duties in particular is set per approval workflow through its self-approval setting. Confirm it on each workflow that gates a key control instead of assuming it applies organization wide.

Requesting reports and completing security reviews

The Trust Center is the fastest path to almost everything a security or vendor-management team asks for:
  1. Visit trust.dualentry.com.
  2. Request access to gated documents (SOC reports, penetration test summary, policies). Access is granted after a clickthrough NDA.
  3. Download the artifact you need, or share the link with your security reviewer.
A SOC report covers a stated observation window rather than a moment, so check the period on the report you download against the period your own reviewer is assessing. Where your review needs coverage of a window the current report does not reach, ask your account team what is available for the gap. Send the reviewer to the Trust Center directly where you can. Gated documents release after a clickthrough NDA, which is normally faster than routing a questionnaire through your account team and back. For a question the Trust Center does not answer, contact your account team with the specific control or clause in hand. A pointed question about one control gets a faster answer than a full questionnaire that mostly repeats what the Trust Center already covers.
Last modified on September 30, 2026