SYS_STATUS: OPTIMAL // DOUBLE-ENTRY: DB-ENFORCED // ANOMALY_DETECTION: ACTIVE // LEDGER_SYNC: REAL-TIME //SYS_STATUS: OPTIMAL // DOUBLE-ENTRY: DB-ENFORCED // ANOMALY_DETECTION: ACTIVE // LEDGER_SYNC: REAL-TIME //SYS_STATUS: OPTIMAL // DOUBLE-ENTRY: DB-ENFORCED // ANOMALY_DETECTION: ACTIVE // LEDGER_SYNC: REAL-TIME //SYS_STATUS: OPTIMAL // DOUBLE-ENTRY: DB-ENFORCED // ANOMALY_DETECTION: ACTIVE // LEDGER_SYNC: REAL-TIME //
Security

Security

How Owwyl protects your financial data.

256Bit Encryption
Security Architecture — Six Layers

Encryption at Rest

All OAuth tokens, transaction data, and invoice PDFs are encrypted using AES-256. Encryption keys are stored separately from application data and rotated on a regular schedule.

Tenant Isolation

Every record carries an organization identifier, and every read and write is scoped to your organization. No screen and no export returns another organization's data. Cross-tenant isolation is verified by an automated test before any release.

Minimum Permissions

Email: read-only via Nylas. Bank: read-only via Stripe Financial Connections. Xero: invoice and account read/write for bill creation only. We never request permissions beyond what the service requires.

Draft-Only Submissions

New categorizations start as drafts. As Owwyl reaches your confidence threshold on confirmed vendors, submissions become automatic. You control the threshold. New vendors always start as drafts.

Token Management

Xero tokens refreshed every 30 minutes. Stripe FC tokens encrypted with AES-256. Email tokens via Nylas stored encrypted with proactive refresh.

Audit Trail

Every sync operation, categorization decision, and anomaly detection event is logged with timestamps, actor, and reasoning. Full audit history available in your account.

Data Access Policy

What Owwyl accesses — and what it never touches.

We Access
Xero chart of accounts
Bank transaction feed
Email invoice PDFs (via Nylas)
Bill and payment status
We Never Access
Personal emails
Bank credentials
Contacts
Calendar
Email drafts
Tenant Isolation
Encrypted at Rest
Append-Only Audit Log
Double-Entry Ledger
Questions?

Questions about our security practices?

Contact security@kronos.ai →
Trust
EncryptionAES-256
LedgerDouble-Entry
Audit LogAppend-Only