Skip to content
Security

How we protect your books and your customers' payments

Merch Invoice holds access to your QuickBooks company and handles your customers' payments. These are the controls we use for both.

Card and bank data

Customers type card and bank account numbers into hosted payment fields provided by our PCI DSS compliant processing partners. Those numbers go straight to the processor and never reach Merch Invoice's servers. We store only a token, the card brand or bank name, the last four digits and the expiry date, so saved payment methods and autopay work without us ever holding full numbers.

QuickBooks access

  • You connect through Intuit's own sign-in page using OAuth 2.0. We never see your Intuit password.
  • We request only the QuickBooks Online accounting permission.
  • A one-time value is checked on every connection, so a forged connection attempt is rejected.
  • Access tokens are encrypted with AES-256-GCM, using a key kept outside the database.
  • Disconnecting revokes our access with Intuit immediately.

Signing in

  • Accounts are created by invitation only. There is no public sign-up.
  • Every user confirms sign-in with a second step.
  • Repeated failed sign-in attempts are rate-limited.
  • Each person has their own sign-in, with owner and staff roles.

Protecting stored data

  • All traffic uses HTTPS, and stored data is encrypted at rest.
  • Every record carries the business it belongs to, and every query is limited to that business.
  • Payment and integration keys are encrypted before they're saved.
  • Logs are scrubbed of keys, tokens and personal details, and errors never expose internal details.

Recording payments once

Notices from QuickBooks and from our processing partners are signature-checked before we act on them. Each one is saved and processed exactly once, so a notice delivered twice can't create a second payment or a second invoice.

Hosting and monitoring

Merch Invoice runs on managed cloud infrastructure in the United States with automated database backups. Failed background jobs are retried and flagged to our team, and every change is tested automatically and released to a staging environment before production.

Report a security issue

If you think you've found a vulnerability, email support@merchly.io with the subject "Security report" and the details. Please give us a chance to fix it before telling anyone else, and don't access data that isn't yours.