Security & compliance

Bookkeeping software: encryption, SSO, and audit logs. Not a bank. Not a custodian.

Enterprise procurement? View / download our Data Processing Agreement (DPA) · System status

What this product is

MizuAlign is bookkeeping and financial analysis software. We help you record, close, and understand your finances.

We do not hold, custody, or transmit your operating funds. Plaid is read-only bank data. Stripe on this site bills for the MizuAlign subscription.

Encryption & data protection

All data is encrypted in transit using TLS 1.2+ and at rest using AES-256 on our PostgreSQL infrastructure.

Authentication tokens and SSO secrets are encrypted with tenant-scoped keys. Enterprise admins can rotate credentials from Settings → Security.

We never sell customer data. You can export or delete your workspace at any time from account settings.

SSO & identity (Enterprise)

Enterprise plans include SAML 2.0 and OpenID Connect (OIDC) single sign-on with Okta, Azure AD, and Google Workspace.

Admins configure identity providers in Settings → Security → SSO. Optional enforcement blocks password login when SSO is required.

SAML metadata is available at your tenant metadata URL for IdP configuration.

Audit log (Enterprise)

Enterprise includes an immutable audit log of security and admin events - SSO changes, role updates, exports, and settings modifications.

Compliance teams can filter by actor, event type, and date range, then export to CSV for retention policies.

Configurable retention cron purges events older than your policy window.

White-label & custom domains

Agencies and MSPs can replace MizuAlign branding with their own logo, colors, and custom domain (CNAME).

Configure white-label settings in Settings → White-Label. Client-facing portal pages inherit your brand.

Client portal

Branded client portal with magic-link authentication - no password required for clients.

Share invoices, proposals with e-sign, and Pay Now flows. Portal settings live under Settings → Portal.

Workflow automation & webhooks

Event-driven automation with delays, retries, and outbound webhooks integrates MizuAlign into your finance stack.

Developer settings include Zapier-compatible endpoints, webhook CRUD, and API keys.

Compliance posture

MizuAlign implements security controls - SSO, immutable audit logs, encryption, and a published DPA. That is honesty about our controls, not a custody or money-transmitter license.

We are not SOC 2 Type II certified today, and we do not claim to be "SOC 2 in progress" until a formal readiness assessment or Type I audit engagement has begun. We do not invent customer quotes or press logos.

Security questionnaires and procurement packages: hello@mizualign.com.

Sub-processors

MizuAlign uses the following sub-processors to deliver the Service. Enterprise customers may request an updated list at hello@mizualign.com.

  • Supabase - PostgreSQL database hosting and authentication infrastructure
  • Stripe - MizuAlign subscription billing — not custody of your operating cash
  • Plaid - Read-only bank and card account connectivity

Multi-entity books

Finance teams can maintain separate legal entities with base currencies and a consolidation hierarchy.

Configure entities under Settings → Legal Entities. Transactions and reports can be scoped per entity.

Tracking dimensions

Add class, location, department, and custom segment tags for granular reporting and budget overlays.

Manage dimensions under Settings → Tracking Dimensions and apply them across expenses and budgets.

E-sign proposals

Create proposals in the workspace and share a secure public link for client review and e-signature.

Signed proposals are stored with the proposal record. Send links from Proposals in your dashboard.

Security contact

Report a vulnerability or request a security review: security@mizualign.com

Enterprise procurement and DPA requests: hello@mizualign.com