Trust and security

Your data, handled the way an accountant would.

M.A. Whately is an Irish firm of Chartered Certified Accountants and Registered Auditors, trusted with clients' figures for over 30 years. The Suite is built to the same standard: your data stays in Ireland, it is encrypted on the way and at rest, every business is walled off from every other, and nothing is filed or sent without a person approving it. Every claim on this page can be checked.

Ireland
where your business records and files are stored
Dublin
where the Suite's application server runs
TLS 1.2 and 1.3
the only connections the Suite accepts, checked 6 Oct 2026
You decide
how long finished records are kept: 3 months to 7 years

Where your data lives

Every provider, what it does and where

The Suite uses a small number of established providers. Each works under a written data processing agreement with the EU standard contractual clauses, and each is listed in ours. Some are US companies whose support staff may access systems from outside the EU under those safeguards.

SupabaseDatabase, sign-in and file storage

Your requests, answers, uploaded files, bills, records and settings. Encrypted in transit and at rest.

Ireland (EU)

VercelApplication server and web pages

Runs the Suite's server code in Dublin. Public pages are delivered from a global network so they load quickly; they hold no client data.

Dublin (EU)

ResendEmail sending

Sends requests, reminders and sign-in emails, from the EU (Ireland) sending region.

Ireland (EU)

AnthropicAI reading and Concierge, only when used

Only when a business uses AI to read a photographed bill or uses the Concierge assistant. Anthropic does not use this data to train its models. It may process requests outside the EU; the safeguards for that transfer are set out in our data processing agreement.

Only if used
Free toolsQuotes, Payment Chaser, Cash Flow, the Compliance Calendar, Receipt Capture and Bank Statements keep what you type in your own browser. Nothing is uploaded unless you sign in to a business account.

How it is protected

Safeguards built into every page

Each business walled off

Row level security in the database keeps every business's records separate, and automated tests check that it holds. M.A. Whately cannot open a client's records unless that business adds the firm.

No passwords to steal

Sign-in is by invitation and a one-time link or code that works once and expires in an hour. Only people a business invites can join it.

Links that expire

Links sent to your customers and staff are long random keys. Each upload uses its own signed link that expires after 2 hours.

Everything logged

Account actions such as people added or removed, role changes, exports and deletions go to an audit log that cannot be edited. Owners can read it at any time.

Yours to take or delete

Owners can download all of their business's data at any time. Finished records are deleted automatically after the period you set; closing an account removes its files and records.

Secrets stay on the server

Keys that can reach all data never leave the server. Connections to Xero are stored encrypted. Pages are served with strict browser security headers.

Encryption

Encrypted on the way, at rest and inside the Suite

Three layers, each labelled with how it is known: checked live against the running Suite, stated by the provider that runs it, or written into the Suite's own code.

Checked live, 6 Oct 2026

In transit

Between your browser and the Suite

  • TLS 1.2 and TLS 1.3 only. Older versions are refused, and every browser Qualys SSL Labs simulates gets forward secrecy.
  • HTTPS enforced. A plain http:// address is redirected to https://, and browsers are told to use HTTPS only for two years, subdomains included (HSTS).
  • Strict browser headers. A content security policy, no framing by other sites, no referrer sent, no MIME sniffing.

See the scan results

Provider's own statement

At rest

Where records and files are stored

  • Supabase (database and files): "All customer data is encrypted at rest with AES-256 and in transit via TLS."
  • Vercel (application server): data encrypted at rest with AES-256 and in transit over HTTPS / TLS.
  • Resend (email): encryption at rest with AES-256 and in transit over HTTPS / TLS.

Read on each provider's security page, 6 Oct 2026: Supabase, Vercel, Resend.

In the Suite's code

Inside the Suite

What M.A. Whately built on top

  • Xero connections are encrypted with AES-256-GCM on the server before they are stored.
  • Request links carry a 192-bit random key; proposal links a 256-bit one. Each upload gets its own signed link that expires after 2 hours.
  • Incoming email and delivery events are accepted only with a valid HMAC-SHA256 signature, and stop links in emails are signed the same way.

Check it yourself

Independent scans you can re-run in a minute

You do not have to take our word for any of this. These free, independent scanners test the live Suite from the outside. The results below are the ones we obtained, with the date; press a link to run the test again today.

Qualys SSL Labs A

TLS 1.2 and 1.3 only, forward secrecy with every browser the test simulates, a 2048-bit certificate, and no known protocol weaknesses (Heartbleed, POODLE, BEAST).

Tested 6 Oct 2026, 15:35 UTC Run the SSL Labs test →
Mozilla HTTP Observatory 11 / 12tests passed

Score 80 out of 100. The one test not passed: the content security policy allows inline scripts, because each Suite tool is a single self-contained file that also works offline. Scripts can still load only from the Suite itself and, at pinned versions, from the public code network cdn.jsdelivr.net.

Tested 6 Oct 2026, 15:21 UTC Run the Observatory scan →
Email authentication DKIM+ SPF

Suite emails are sent from send.mawhately.ie through the EU (Ireland) sending region, signed with a DKIM key published at resend._domainkey.mawhately.ie, and covered by an SPF record. Receiving mail servers can check that a Suite email is genuine.

DNS checked 6 Oct 2026 Look up the DKIM record →
For the technically minded. The headers every page is served with, as returned on 6 October 2026. Run this in any terminal to see them yourself:
curl -sI https://suite.mawhately.ie
Headers present
  • Strict-Transport-Security
  • Content-Security-Policy
  • X-Frame-Options: DENY
  • X-Content-Type-Options
  • Referrer-Policy: no-referrer
  • Cross-Origin-Opener-Policy
  • Permissions-Policy

AI, used carefully

AI does the reading. A person makes the decisions.

AI saves real time on reading bills and answering questions. These are the rules it works under in the Suite.

The rules

  • Free reading first. A digital PDF is read in your browser. AI is used only for photos and scans, or when the free reading fails its checks.
  • Every reading is checked. VAT sums per rate, Irish VAT rates, VAT number check letters, dates and duplicates. Anything flagged waits for a person.
  • Documents are data, not instructions. Text inside a bill or email can never tell the AI to do something.
  • Not used for training. Anthropic's Commercial Terms say it "may not train models on Customer Content from Services".
  • Asks before acting. The Concierge assistant shows you what it will send or change, and waits for you to confirm.
  1. You upload or ask

    A photo of a bill, or a question such as "which invoices are overdue?".

  2. The Suite reads and checks

    The answer is checked against your own records and Irish rules, and anything unclear is marked for you.

  3. You approve

    Nothing is sent to Xero, posted or emailed to a customer until a person says so.

If you leave

What happens to your data if you stop using the Suite

Leaving should be as easy as joining. Your data is yours, in a format you can open, and it goes when you go.

  1. Take a full copy

    An owner or admin presses Download all data in Settings. The file holds requests, answers, contacts, templates, people, the timeline and your tools' data, with links to every file that work for 24 hours.

  2. Tell M.A. Whately

    Email info@mawhately.ie or ring 041 685 3162 and ask for the account to be closed.

  3. Everything is deleted

    Closing the account deletes its files, logo and every record from the live system, and the deletion is written to the audit log.

  4. Or keep less all along

    Finished requests are deleted with their files after the period you set, from 3 months to 7 years, and you can delete any request yourself at any time.

GDPR and your rights

Clear roles, written down

  • Who is responsible

    For the records your business keeps in the Suite, your business is the controller and M.A. Whately is the processor, acting only on your instructions. Our data processing agreement sets this out in full, in line with Article 28 of the GDPR.

  • If something goes wrong

    The agreement commits M.A. Whately to tell you about any personal data breach affecting your data within 48 hours, and to help you with any report to the Data Protection Commission.

  • People's rights

    Access, correction, deletion and a copy of data can be handled from the Suite itself, and we help where they cannot.

  • Sub-processors

    The providers above are the full list. We tell business owners in advance before adding or replacing one.

  • Raising a concern

    Contact us first and we will put it right. You can also contact the Data Protection Commission at dataprotection.ie.

For your IT or compliance team

Answers to the questions a supplier security review asks

Where is data hosted?
Database, sign-in and files: Supabase, in the AWS West EU (Ireland) region. Application server: Vercel, Dublin region. Email: Resend, EU (Ireland) sending region. Public pages hold no client data and are served from Vercel's global network.
Who can get in?
Only people a business invites; public sign-up is switched off. Each person has a role (owner, admin or staff). Row level security in the database keeps each business's records to its own members, and the firm's staff cannot open a business's requests or files through the Suite unless the business adds the firm as a member.
How do people sign in?
With a one-time link or 6-digit code sent to their email, which works once and expires in an hour. There are no passwords to leak or reuse. Because the email inbox is the key, we recommend multi-factor sign-in on every email account that uses the Suite.
Is data encrypted?
Yes, in transit (TLS 1.2 and 1.3 only, HSTS) and at rest (AES-256, as stated by Supabase, Vercel and Resend). Xero connections are additionally encrypted by the Suite with AES-256-GCM. Details.
What is logged?
Every action on a request is logged on its timeline. Account actions (people, roles, invitations, package changes, exports, deletions) go to an audit log that cannot be edited, readable by owners and admins. Actions taken through the Concierge assistant are logged with that source.
How are uploaded files handled?
Files are kept in private storage, readable only by members of the business that owns them. Files sent through request links arrive through server-issued signed links, are limited by type and size, and download as attachments rather than opening in the browser.
What if there is a breach?
Under our data processing agreement M.A. Whately tells the affected business within 48 hours of becoming aware of a personal data breach, with what is known, and helps with any report to the Data Protection Commission.
Retention, deletion and export
Each business sets how long finished requests are kept (3 to 84 months, 24 by default); the daily job then deletes them with their files. Concierge conversations are deleted after 30 days. Owners and admins can download all data at any time. If you leave.
Is AI used, and on what?
Only where a business uses it: reading photos and scans of bills, and the Concierge assistant. Requests go to Anthropic's API, which under its Commercial Terms may not train on them. A person approves anything that is sent, posted or filed. The rules.
How is the code tested?
An adversarial security review on 23 September 2026 led to fixes, each with a regression test. The backend checks (232 on 1 October 2026) cover isolation between businesses, the firm's no-access rule, link scoping, upload confirmation and paused accounts.
Certifications
M.A. Whately itself does not hold an information security certification such as ISO 27001 or SOC 2. The providers that host the Suite do; their reports are listed below, as each provider states them.
Administrative access
As with any hosted service, the people who run the Suite's infrastructure can reach the database outside the application. The data processing agreement governs that access, and keys that can reach all data are kept on the server and never sent to a browser.
Sub-processors, checked on each provider's site on 6 October 2026
ProviderWhat it doesWhereProvider's own security statementsLinks
Supabase, Inc.Database, sign-in, file storageAWS West EU (Ireland)SOC 2 Type 2 compliant, ISO 27001 certified, AES-256 at restSecurity · DPA
Vercel Inc.Application server, web pagesDublin (functions); global network for public pagesSOC 2 Type 2 attestation, ISO 27001 certified, certified under the EU-US Data Privacy Framework, AES-256 at restSecurity · DPA
ResendEmail sendingEU (Ireland) sending region; account data in the USSOC 2 Type II, transfers under the standard contractual clauses and the EU-US Data Privacy Framework, AES-256 at restSecurity · DPA
Anthropic, PBCAI reading of photos and scans, Concierge (only when used)May process outside the EUCommercial Terms: may not train models on customer contentTrust Center · Terms

Certifications belong to each provider, not to M.A. Whately; the wording is the provider's, from the pages linked. Ask for our data processing agreement for the full list with transfer safeguards.

Responsible disclosure

Found a security problem? Tell us privately.

How to report it

  • Email info@mawhately.ie with "Security report" in the subject, what you found and how to reproduce it.
  • Please do not open, change or keep data that is not yours, and stop as soon as you see someone else's information.
  • No denial of service, spam or social engineering of staff or clients.
  • Give us a reasonable time to fix it before telling anyone else.

Our contact details are also published in the standard machine-readable form at /.well-known/security.txt.

Now check your own business

The Suite is one link in the chain; email, passwords and backups are the others. The free Cyber Health Check takes 10 minutes and gives a fix list for Microsoft 365 or Google Workspace.

Start the Cyber Health Check →

Questions about your data? Email info@mawhately.ie or call 041 685 3162 (Monday to Friday, 8.30am to 5pm). Read the firm's privacy policy. M.A. Whately & Co. Unlimited Company, CRO 466004, Greenville, Jervis Street, Ardee, Co. Louth, A92 KH36.

Last reviewed 6 October 2026. Scan results are dated; provider statements were read on the providers' own pages that day.