Feature
The board can never edit history. Neither can we.
An append-only, hash-chained audit log anchored to an external timestamp authority; money controls enforced in the database; mandatory two-factor authentication for financial roles; Canadian data in Canada and US data in the US.
Board reality
Why this is hard for a volunteer board
A volunteer board holds the owners' money with no internal audit function. The controls that protect a company's treasury have to come from the software.
The mechanism
How the butler handles it
- Step 1
Every action joins a chain
Including reads of sensitive records. Altering any entry breaks the chain, and a nightly anchor makes even operator tampering detectable. - Step 2
Money controls sit in the database
Dual authorisation with thresholds from your bylaws, positive-pay files, a vendor bank-change lock with callback by a second person, a new-vendor cooling period, anomaly detection, quarterly access review, and a confidential whistleblower channel. - Step 3
Financial roles carry two-factor
Treasurer, President, bookkeeper and our own staff must use it. Treasury actions require step-up, and support impersonation needs your consent and is fully logged.
Record output
What it produces
The audit chain and a sealed evidence package, plus the internal control self-assessment for your auditor.
Fraud controls, a fidelity coverage adequacy check, and bank feeds and reconciliation with an exception queue.
Treasury tools: a GIC and CD ladder against capital outflows, insured deposit coverage, interest earned on reserves, a liquidity forecast, and investment policy against statutory eligible securities.
Data residency, field-level encryption, session and device management, and a full export at any time.
Rules pack
Ontario and Florida
Each jurisdiction is a rules pack, and the citation travels with the obligation.
Canadian corporations' data lives in Canada, in the Montreal region. US associations' data lives in the US. Privacy obligations under PIPEDA and applicable state laws are documented on the Privacy page.
Board questions
Questions boards ask
Do you hold a SOC 2 report?
Not yet. We run a SOC 2 readiness programme: written policies, evidence collection and annual penetration testing. We will publish the auditor's report when one exists, and we claim nothing about an audit before then.
Where is our data?
Canada for Canadian corporations, the United States for US associations. See the Subprocessors page for every vendor.
Can we leave?
Yes, any time, with a complete export in open formats including the audit chain and its verifier.
Set your corporation up this afternoon
An append-only, hash-chained audit log anchored to an external timestamp authority; money controls enforced in the database; mandatory two-factor authentication for financial roles; Canadian data in Canada and US data in the US.