Security & privacy

Security & privacy

How OneHQ protects your practice and client data — encryption, access controls, data isolation, and compliance.

Overview

OneHQ is built for Australian accounting practices handling sensitive financial data — ABNs, TFNs, bank details, payroll records, and tax lodgement information. Security is built into every layer of the application, from infrastructure to application design.

All data is hosted in Australia. The platform is designed around the principle of least privilege — every user, integration, and system component has access only to what it needs, and nothing more.

Key security measures include:

  • Australian-hosted infrastructure — all data stays onshore
  • Practice-scoped isolation — every request is bound to one practice before it reaches any data
  • Encryption at rest and in transit — TLS/HTTPS everywhere
  • Role-based access control — four configurable roles (Partner, Accountant, Administration, Bookkeeper) with granular permissions
  • Immutable audit logging — 7-year retention
  • OAuth 2.0 integrations — minimum required scopes, revocable at any time
ATO DSP registration. OneHQ is currently applying for ATO Digital Service Provider registration, built to meet DSP Operational Security Framework requirements from day one.

Data hosting

All data is hosted on Australian infrastructure via Amazon Web Services (RDS PostgreSQL, Sydney — ap-southeast-2). No data is processed offshore or routed through overseas data centres.

This includes:

  • Client data — entities, contacts, ABNs, TFNs, financial records, jobs, billing
  • Authentication data — user accounts, sessions, JWT tokens
  • File metadata — document references, signing records, communication logs
  • Audit trails — security logs, integration authorisation records

File storage (documents, signed PDFs) stays in your own Dropbox or OneDrive/SharePoint, which provides its own enterprise-grade security and encryption. Your practice controls the connected account and can disconnect at any time.

Practice isolation

Every practice’s data is isolated. Practice A cannot see, query or access Practice B’s data.

Every record in the database carries the practice that owns it. Every authenticated request is resolved to exactly one practice before it is allowed to reach any data, and every query is scoped to that practice. This means:

  • A user can only read rows belonging to their practice
  • Queries that attempt to access another practice's data return zero results
  • Access is enforced on the server, on every request — it is not something the browser can ask to skip
Tip: practice isolation is only half of it. Within a practice, access can be narrowed to the clients a staff member is assigned or explicitly granted — and a specific client can be withheld from a specific staff member entirely.

Authentication & access control

AWS Cognito handles authentication with email and password. A signed-in session is held in a server-side session store and carried by a secure, HTTP-only cookie — no long-lived credential is kept in the browser where a script could read it.

Role-based access control

Every staff member is assigned one of four roles, each with configurable permissions:

  • Partner — full access to clients, jobs and settings
  • Accountant — access to assigned clients and jobs
  • Administration — reception and administration: the whole client list by name, with financial detail scoped to assignment
  • Bookkeeper — access scoped to bookkeeping work and its clients

Permissions are configurable per role in Settings > Users & Permissions. Admins can customise what each role can see and do across the application.

Session management

Active sessions are tracked and can be reviewed by administrators. Sessions can be revoked to force a user to re-authenticate. Session tokens are automatically refreshed and expire after inactivity.

Invite-based onboarding

New staff members are added via invite links, ensuring only authorised people can join a practice. Invite tokens are single-use and hashed using SHA-256 before storage.

Encryption

Data is encrypted at rest and in transit:

  • At rest — AWS provides managed encryption for all stored data, including backups
  • In transit — all connections use TLS/HTTPS. API calls between the frontend, backend, and external services are encrypted end-to-end

Sensitive fields such as Tax File Numbers (TFNs) are handled with additional care in accordance with the Privacy (Tax File Number) Rule 2015. OAuth tokens for integrations (Xero, Dropbox, Gmail, Microsoft) are stored encrypted and are never exposed to the frontend.

Audit logging

An immutable audit log records security-relevant actions across the practice. The audit_log table is practice-scoped and append-only — entries cannot be modified or deleted, even by administrators.

Logged actions include:

  • User authentication events (login, logout, failed attempts)
  • Permission changes and role assignments
  • Integration connections and disconnections
  • Data access and modification events
  • Session management actions (revocation, expiry)

Audit logs are retained for 7 years per ATO DSP requirements, providing a complete trail for compliance reviews and security investigations.

AML/CTF compliance

OneHQ includes a built-in AML/CTF verification module for identity verification of clients and associated persons. This supports accounting practices in meeting their obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006.

The module supports:

  • Primary and secondary ID verification — record and track identity documents for each person
  • Customer Due Diligence (CDD) levels — standard, simplified, and enhanced due diligence workflows
  • Sanctions checking — flag and record sanctions screening outcomes
  • Reverification schedules — configurable reverification periods with automatic reminders
  • Escalation workflows — route complex or high-risk verifications for senior review

AML/CTF settings are configurable per-practice in Settings > AML/CTF. You can enable or disable the module, configure designated services, set reverification periods, and choose whether to require secondary identification.

All AML/CTF actions are logged in a dedicated audit trail (aml_audit_log), separate from the general audit log, providing a complete record of verification activities for regulatory review.

Integration security

All integrations use OAuth 2.0 with the minimum required scopes. OneHQ never stores third-party passwords — only OAuth tokens, which can be revoked at any time.

Xero

OneHQ reads Xero to power its compliance work, and writes back only where you ask it to — posting a journal an accountant has reviewed, or authorising a draft invoice you choose to send. It never touches contacts, bank feeds or pay runs. See the Xero integration guide for full details.

File storage — Dropbox or OneDrive

File storage and document management run on your practice's own Dropbox or OneDrive/SharePoint. OAuth access is scoped to the connected account, and file operations are performed on behalf of the authenticated user.

Email providers (Gmail / Microsoft)

Email sending for campaigns uses OAuth 2.0 with Gmail or Microsoft Graph APIs. Only the minimum send-related scopes are requested. Email content is rendered server-side and sent directly via the provider's API.

SMS

OneHQ sends SMS over its own secure messaging platform by default; a practice can also connect its own ClickSend or Twilio account. Any credentials are stored encrypted and configurable in Settings.

Token management

All OAuth tokens are stored encrypted in the oauth_tokens table, scoped to the practice. Tokens are automatically refreshed when they expire. You can revoke any integration at any time from Settings > Connections.

Integration authorisation events (connect, disconnect, token refresh) are logged in the integration_authorizations audit trail, providing a complete record of which staff member authorised each connection and when.

Frequently asked questions

All data is hosted in Australia on Amazon Web Services infrastructure in the Sydney (ap-southeast-2) region. No data is processed or stored offshore. This includes client data, authentication records, audit logs, and all attachments.

OneHQ uses a service role for backend operations, and that access is controlled and audited. Every request is resolved to a single practice before it can reach data, so a backend query is scoped to that practice in the same way a user request is.

Go to Settings > Connections and click Disconnect on the relevant integration. This revokes the OAuth token and unlinks the service from your practice. The disconnection is logged in the integration authorisation audit trail.

We are currently applying for ATO DSP registration. OneHQ is built to meet DSP Operational Security Framework requirements, including Australian data hosting, audit logging with 7-year retention, encryption at rest and in transit, and access controls aligned with the framework's expectations.

Have a security question or concern?

Get in touch