Skip to content
AccountingKit
WorkflowsAPIUse casesPricingDocs
Log in
WorkflowsAPIUse casesPricingDocsLog in

Legal

Acceptable Use Policy

AccountingKit writes entries into real books and holds credentials to real accounting systems. This policy exists so that one customer's misuse cannot put another customer, a provider, or the platform at risk.

Version
1.0
Effective
1 September 2026
Questions
security@accountingkit.dev

On this page

  1. Scope
  2. Prohibited use
  3. Provider obligations
  4. Technical limits
  5. Security testing
  6. Enforcement
  7. Reporting abuse

Scope

This policy applies to everyone who uses AccountingKit: your organization, your personnel, and anyone you give access to through your API keys or your own product. You are responsible for their conduct as if it were your own. It is incorporated into the Terms of Service.

Prohibited use

Do not use AccountingKit to:

  • Break the law, including tax, accounting, securities, sanctions, export control, anti-money-laundering, or data protection law in any jurisdiction that applies to you.
  • Create, alter, or conceal accounting entries in order to misrepresent a financial position, evade tax, launder money, or defraud an investor, lender, auditor, or authority. Automating bookkeeping is the product. Automating falsification is not.
  • Access an accounting organization you are not authorized to access, or retain access after that authorization ends.
  • Process personal data without a lawful basis, or send us special category data, payment card numbers, or government identity documents that the service does not require.
  • Send malware, attempt to gain unauthorized access to the service or to another customer's data, probe or circumvent authentication, tenant isolation, or rate limits, or reverse engineer the service except where law expressly permits it.
  • Resell, sublicense, or expose raw API access as a standalone product without a written agreement permitting it, or use the service to build a directly competing unified accounting API.
  • Interfere with the service's operation, including by generating load designed to degrade it or by using it to attack a third party.
  • Misrepresent your identity or your affiliation with AccountingKit, or imply an endorsement, certification, or partnership that does not exist.

Provider obligations

Your use of a connected accounting platform through AccountingKit must comply with that platform's terms and developer policies, including its rate limits, scope requirements, branding rules, and restrictions on data extraction. A provider can terminate its own access independently of us, and we must act on a provider's instruction to suspend a connection that breaches its terms.

Only request the OAuth scopes your use actually needs. Broad scopes on a live connection are the single largest avoidable risk in an accounting integration.

Technical limits

  • Respect rate limits, both ours and your provider's. Back off on a 429 response rather than retrying immediately; the service already retries durable work on your behalf.
  • Send an idempotency key on every mutation. This is what prevents a retried write from creating duplicate ledger entries.
  • Do not poll where a webhook exists, and do not use synchronous live reads to replicate a full dataset that a sync is designed to move.
  • Keep live and test workloads in their own environments. Load testing belongs in test, against a provider organization you own.
  • Verify the signature on every webhook you receive from us before acting on it.

Security testing

We welcome good-faith security research, subject to rules that keep it from becoming an incident. Test only against your own test environment and your own provider organizations. Do not run automated scanners against production, do not attempt denial of service, do not access another customer's data, and stop as soon as you have confirmed a finding.

Report what you find to security@accountingkit.dev and give us reasonable time to fix it before disclosing publicly. Research that follows these rules will not be treated as a breach of this policy, and we will not pursue action over it. See the disclosure policy for details.

Enforcement

Where we can, we will contact you and give you a chance to fix the problem. Where the risk to another customer, to a provider, or to the platform does not allow that, we may suspend a key, a connection, or an account immediately and tell you as soon as practicable.

Suspension is limited to what the circumstance requires — usually a single key or connection rather than the whole account. Repeated or deliberate breach may lead to termination under the Terms of Service. We report to authorities only where the law requires it.

Reporting abuse

If you believe someone is using AccountingKit in breach of this policy, write to security@accountingkit.dev with enough detail to investigate. We will look into every credible report.

Related

Terms of ServiceThe contract that governs access to the API, the console, and workflow execution.Privacy PolicyWhat personal data AccountingKit handles, why, where it lives, and for how long.Data Processing AddendumArticle 28 processor terms, the processing record, security measures, and transfer safeguards.SubprocessorsEvery third party in the processing chain, what it touches, and where it runs.Cookie NoticeThe marketing site sets no cookies. The console sets one, and it is essential.SecurityThe controls behind the platform, stated plainly, including the ones not yet certified.
AccountingKit

Accounting workflows for the systems businesses already use.

hello@accountingkit.dev
ProductWorkflowsUnified APIUse casesPricing
DevelopersDocumentationDeveloper consolellms.txt
CompanyFAQSecurityReport a vulnerability
LegalTermsPrivacyDPASubprocessorsAcceptable useCookies
© 2026 AccountingKit. All rights reserved.AccountingKit is an independent product and is not affiliated with, endorsed by, or sponsored by any accounting software vendor. Xero is a trademark of Xero Limited. QuickBooks is a trademark of Intuit Inc. Sage and Sage Intacct are trademarks of The Sage Group plc. FreshBooks and Wave are trademarks of their respective owners, as are all other product names and marks used here for identification only.