Small businesses and accounting professionals trust GlassJar with sensitive financial information š”ļø
Our security program is built around three core tenets
Least-privilege access: Role-based access controls ensure users and systems receive only the permissions necessary to perform their tasks.
Encryption: Data is protected in transit and at rest using industry-standard encryption.
Auditability: Activity is logged and monitored to support accountability, investigation, and compliance.
Here is how we put those principles into practice.


Your books are yours
GlassJar staff cannot access your books unless you grant them access.
Access must be authorized through an invitation from the customer. Every change is recorded in a customer-visible activity trail, allowing you to see what happened and who performed the action.
How your financial connections work
Bank connections through Plaid
GlassJar uses Plaid Link to connect the financial accounts you authorize. Your bank sign-in takes place within Plaid, and GlassJar never receives your bank credentials.
GlassJar stores only the Plaid access token required to retrieve the account and transaction information you authorize. The integration is designed to read financial data and cannot initiate the movement of money.


Invoice payments through Stripe
GlassJar uses Stripe to securely collect payment details and Stripe Connect to support businesses accepting invoice payments.
GlassJar complies with the Payment Card Industry Data Security Standard (PCI DSS). Card processing is handled by Stripe, a PCI DSS Level 1 service provider, the most stringent certification level in the payments industry.
Payment card data and sensitive authentication data never enter GlassJar systems. We receive only the payment information needed to support accounting workflows, such as the payment status, amount, and transaction reference.
Each connected business is the merchant for its own invoice payments and is responsible for its processing fees, refunds, disputes, and payment support. Businesses can manage payments through both the Stripe Dashboard and the Stripe features embedded within GlassJar.
How we protect your information
Encryption
GlassJar protects data in transit using TLS 1.3 and industry-standard authenticated encryption. Our primary database and customer-file storage use industry-standard encryption at rest.
Controlled access
GlassJar uses role-based permissions to control access to accounting and administrative functions.
Activity records
GlassJar records application activity to support auditability, investigation, and accountability.
Backups
Our primary database is configured for automated daily backups with 35 days of retention.
Infrastructure
GlassJar application infrastructure is hosted by Amazon Web Services in the United States. This does not guarantee that every third-party vendor or data transfer remains within the United States.

Authentication
GlassJar supports single sign-on through Google. When you sign in with Google, your account benefits from any multi-factor authentication protections enabled on your Google account.
Direct email-based authentication is also available.
Account access and data lifecycle
Canceling your subscription does not immediately delete your data. When an account is canceled, it moves to read-only access, allowing you to continue viewing your existing data and accounting reports.
Your information remains available until you request its deletion.

Report a security vulnerability
If you believe you have discovered a security vulnerability in GlassJar, email support@glassjar.io. Reports are routed to our technology team for triage and response.
We appreciate responsible disclosure and will work with you to investigate anything you find.
Security reviews and questionnaires
Evaluating GlassJar for your accounting practice or your clients? Contact us for current information or assistance completing your security questionnaire.










