Enterprise Security Whitepaper

Security, Encryption & Privacy Architecture

How Heirview protects your company's QuickBooks Online credentials, prevents data leakage, and ensures regulatory compliance.

AES-256-GCM Encryption

Every OAuth access token and refresh token is encrypted at rest using Galois/Counter Mode with unique 12-byte IVs and 16-byte authentication tags.

Zero Financial Storage

We never store your invoices, general ledger, customers, or financial records on our disks. All queries stream live between Intuit and your client applications.

OAuth 2.0 with PKCE

Authorization flows use Proof Key for Code Exchange (S256) preventing authorization code interception attacks and replay attempts.

1. Multi-Tenant Cryptographic Isolation

Every customer organization is partitioned by its unique QuickBooks Online Realm ID and Zendesk Subdomain. Database rows are indexed strictly by tenant identifier. When a request enters the API, constant-time SHA-256 hash checks verify the caller's authorization header before any cryptographic operation or database read can occur.

2. Single-Use Token Rotation & Alert Engine

Intuit invalidates old refresh tokens upon every refresh operation. Heirview uses atomic write transactions to guarantee that rotated refresh tokens are persisted in encrypted storage before returning control to the caller. Rolling 100-day window health checks emit automated alerts at 60, 30, and 7 days prior to expiry, ensuring zero unexpected service interruption.

3. Cloudflare Edge Network Protection

All Heirview backend endpoints run across Cloudflare's global edge network with automatic TLS 1.3 termination, unmetered DDoS mitigation, and edge rate-limiting token buckets (500 requests/minute per realm with concurrency semaphores) to protect your QuickBooks API quotas.