Security, Encryption & Privacy Architecture
How Heirview protects your company's QuickBooks Online credentials, prevents data leakage, and ensures regulatory compliance.
AES-256-GCM Encryption
Every OAuth access token and refresh token is encrypted at rest using Galois/Counter Mode with unique 12-byte IVs and 16-byte authentication tags.
Zero Financial Storage
We never store your invoices, general ledger, customers, or financial records on our disks. All queries stream live between Intuit and your client applications.
OAuth 2.0 with PKCE
Authorization flows use Proof Key for Code Exchange (S256) preventing authorization code interception attacks and replay attempts.
1. Multi-Tenant Cryptographic Isolation
Every customer organization is partitioned by its unique QuickBooks Online Realm ID and Zendesk Subdomain. Database rows are indexed strictly by tenant identifier. When a request enters the API, constant-time SHA-256 hash checks verify the caller's authorization header before any cryptographic operation or database read can occur.
2. Single-Use Token Rotation & Alert Engine
Intuit invalidates old refresh tokens upon every refresh operation. Heirview uses atomic write transactions to guarantee that rotated refresh tokens are persisted in encrypted storage before returning control to the caller. Rolling 100-day window health checks emit automated alerts at 60, 30, and 7 days prior to expiry, ensuring zero unexpected service interruption.
3. Cloudflare Edge Network Protection
All Heirview backend endpoints run across Cloudflare's global edge network with automatic TLS 1.3 termination, unmetered DDoS mitigation, and edge rate-limiting token buckets (500 requests/minute per realm with concurrency semaphores) to protect your QuickBooks API quotas.