SECURITY

Security and backup limitations

The safeguards CloseBook currently uses and the limitations users must plan for.

Last updated: 26 July 2026

Current safeguards

Administrative access control

CloseBook uses role-based administrative access. Financial book content is not automatically available to every administrator. Authorized access requires the relevant permission and a documented reason, and sensitive access, export and modification operations are recorded for review.

Administrative book changes use revision checks, pre-change snapshots and audit records. Administrator changes do not automatically sign the book owner out; stale versions are rejected and must reload the latest cloud revision.

What security does not guarantee

No online service can guarantee absolute security, uninterrupted availability or recovery from every event. Browser extensions, malware, compromised email accounts, weak reused passwords, device loss, provider outages and user mistakes can still cause loss or unauthorized access.

Guest-mode limitations

Guest books are not protected by an account and are not synchronized. Anyone with access to the browser profile may be able to access them. Clearing browser data can destroy them permanently.

Registered-account limitations

Synchronization improves continuity between devices but is not an independent archival backup. Account access depends on the user's email account, password and the availability of the service and its providers.

User backup responsibility

Document files

CloseBook does not currently store invoice or receipt files. Users must maintain those files separately under their own retention and access-control process.

Reporting a security concern

Submit a Security report through the CloseBook support form. Do not include passwords, verification codes, reset codes or full sensitive financial records.