Security & Privacy

Icon
How Actuals protects customer data, integrations, and access — including SSO via third-party IAM.

Platform

Actuals is ISAE 3402 certified. Controls cover backups, secure data transport, monitoring, and more. Customer data lives in separated environments with dedicated credentials. Actuals runs periodic security audits (including penetration tests).
The web app is available only over HTTPS. Multifactor login is encouraged. For specific security questions, contact support@actuals.io.

Integrations

Actuals connects to data sources in three main ways:
  • (REST) API — for near real-time transactional data (API key per administration; HTTPS required)
  • SFTP — for periodic file exchange
  • Source-specific connectors — when Actuals actively collects from a vendor (often OAuth or similar)
HTTPS protects API traffic end-to-end (no need to re-encrypt payloads for transport). SFTP uses comparable encryption for file transfer. See Import › Data integration for method guides.

Sensitive information

When sharing transaction data, prefer limiting personal data. Matching typically needs unique transaction ids — not full customer PII — as long as the id can be found in other sources. Data is stored encrypted. On-premise deployment can be discussed if required.

Identity & access (SSO)

Use a third-party IAM provider to centralize login and provisioning.
Third-party Identity & Access Management (IAM)Third-party Identity & Access Management (IAM)

Related in the new app

  • Administration › Users
  • Profile settings (SCIM may make some fields read-only)
  • Getting started › Sign in