Security & Trust
Our customers trust us with their accounting and financial data, and we take that responsibility seriously. Spread is certified by Xero and listed on the Xero App Store. This page sets out the security practices we follow.
Hosting
Spread is hosted on private infrastructure based in London, UK. All data storage and processing takes place within the UK.
-
Daily backups are taken, with weekly offsite backups of full server images, so data can be restored if needed
Network & Server Access
Our production server is not reachable from the public internet. Access is only possible through a private VPN, and server login requires cryptographic key authentication rather than a password, meaning only devices holding an authorised private key can connect.
Encryption in Transit
All traffic between your browser and Spread is encrypted using TLS 1.2 or higher.
Sub-processors
We keep the number of third parties who can see customer data to a minimum, these are:
-
Xero - your connected accounting data, used to power the Service
-
Stripe - email address and internal customer ID, for billing
-
Wix - email address and name, for our website and marketing tools
A server health monitoring tool receives only infrastructure metrics such as uptime, and never sees customer data.
User Accounts & Internal Access
Users log in to Spread exclusively via Xero. Because Xero requires two-factor authentication to sign in, every Spread session is protected by the same 2FA requirement, and Spread never stores or manages your password.
When you invite other users to collaborate in Spread, they sign in using their own Xero account and are subject to the same two-factor authentication requirement.
Data
Your data belongs to you. Spread retrieves the data it needs from your connected Xero organisation in order to run the Service, and automates the creation of accounting journal entries for accruals, prepayments, deferred revenue, and recurring bills based on rules you configure. Spread never posts an entry back to Xero without being configured to do so by you or your designated finance professional.
What we Read:
-
User name and email address, for any users invited to Spread.
-
Chart of Accounts
-
Tracking Categories
-
Tax Rates
-
Contacts: including business name, contact email, business number, tax identifier.
-
Invoices, Bills, Spend Money, Recieve Money and Credit Notes, plus Payments applied to them.
-
Journals
What We Write:
Journal entries, contacts, chart of accounts back to Xero.
Data Retention:
Data is retained for the duration of your subscription and deleted after account closure
Billing
Your card and billing information is transmitted and stored securely by our third-party payment processor, Stripe. Spread does not store card numbers.
Privacy
For more detail on how we collect, use, and protect personal data, see our Privacy Policy.
Questions
If you have a specific security question, or need information for a due diligence review, contact hello@spread.finance.
