Security and trust

Built around the evidence a close needs.

ErgoBase is a trust product. The security story starts with narrow data intake, tenant isolation, append-only audit events, and locked-period immutability.

Locked-period immutability

Locked accounting periods are protected by database triggers, not only application logic.

Append-only audit trail

Audit events are designed so they cannot be updated or deleted after creation.

Tenant isolation

Workspace data is scoped server-side and protected with Postgres row-level security using FORCE.

Financial-data boundary

ErgoBase handles financial source records. It does not ingest fan messages, inbox content, media, vault content, or scripts.

Authentication

User authentication is handled through Clerk.

Encrypted evidence storage

Source files, statements, and accountant packs are stored in Cloudflare R2 when production storage is configured.

Data boundary

Financial records only.

The product is not a fan-message tool, media vault, CRM, direct payment processor, or legal/tax advisory system.

Explicitly out of scope

  • Fan messages, fan notes, inbox content, scripts, vault/media content, and sexual content.
  • Direct money movement, direct bank API connections, tax filing, legal advice, and lending decisions.
  • Unshipped named integrations or FX conversion claims.