How Actuals protects customer data, integrations, and access — including SSO via third-party IAM.
Platform
Actuals is ISAE 3402 certified. Controls cover backups, secure data transport, monitoring, and more. Customer data lives in separated environments with dedicated credentials. Actuals runs periodic security audits (including penetration tests).
The web app is available only over HTTPS. Multifactor login is encouraged. For specific security questions, contact support@actuals.io.
Integrations
Actuals connects to data sources in three main ways:
- (REST) API — for near real-time transactional data (API key per administration; HTTPS required)
- SFTP — for periodic file exchange
- Source-specific connectors — when Actuals actively collects from a vendor (often OAuth or similar)
HTTPS protects API traffic end-to-end (no need to re-encrypt payloads for transport). SFTP uses comparable encryption for file transfer. See Import › Data integration for method guides.
Sensitive information
When sharing transaction data, prefer limiting personal data. Matching typically needs unique transaction ids — not full customer PII — as long as the id can be found in other sources. Data is stored encrypted. On-premise deployment can be discussed if required.
Identity & access (SSO)
Use a third-party IAM provider to centralize login and provisioning.
Related in the new app
- Administration › Users
- Profile settings (SCIM may make some fields read-only)
- Getting started › Sign in