Security

Effective September 4, 2026

Your books, your customer and vendor details, and your payment activity are sensitive. Here’s a plain description of how Xtreme Book protects them — not a marketing checklist, an honest account of what’s actually in place today.

1. Encryption

  • All traffic to and from Xtreme Book is encrypted in transit over HTTPS/TLS — there is no unencrypted path into the app.
  • Your database is encrypted at rest by our hosting provider’s managed infrastructure.
  • Passwords are never stored in plain text. We store a salted, one-way bcrypt hash, so we cannot see or recover your actual password — not even to help you if you lose it (you’ll reset it instead).

2. Account access

  • Sign in with a password, or with Google or Facebook single sign-on — we never see or store your Google/Facebook password.
  • Email verification and passwordless email-link sign-in are supported for accounts that want it.
  • Sessions are short-lived, signed tokens; signing out or changing your password invalidates them.

3. Multi-tenant isolation

Xtreme Book is multi-tenant: many organizations share the same application, each with its own isolated data. Every request is scoped to the signed-in user’s organization at the database query level — there is no code path in the app that lets one organization’s data be read or written by another.

4. Role-based access control

Within an organization, four roles — Owner, Accountant, Supervisor, and Staff — govern what each team member can see and do, from full financial and settings access down to day-to-day transaction entry. An organization’s Owner controls who holds which role.

5. Audit trail

Xtreme Book keeps an audit log of who created, edited, voided, or deleted significant records, and when — visible to your organization under Accounting > Audit Trail. Login activity, including any platform-support access described below, is also logged.

6. Payments

Card and Mobile Money payment details are handled entirely by Flutterwave, a licensed payment service provider — Xtreme Book never receives or stores full card numbers, mobile money PINs, or other sensitive payment credentials. We only store the resulting transaction reference, amount, and status.

7. Platform support access

A small number of authorized Xtreme Book staff can access the Super Admin area to provide support, investigate abuse, or fix an account issue. Every such action — including impersonating a user to troubleshoot on their behalf — is written to a separate, tamper-evident admin audit log distinct from your organization’s own audit trail.

8. Backups & availability

Our database is backed up regularly by our hosting provider so that data can be restored in the event of an infrastructure failure. See our Terms of Service for our current availability commitment.

9. Vulnerability disclosure

If you believe you’ve found a security vulnerability in Xtreme Book, please report it to security@xtremebook.com before disclosing it publicly. Give us a reasonable chance to investigate and fix it, and don’t access, modify, or delete data that isn’t yours while testing. We’ll acknowledge your report and keep you updated as we work on it.

10. Your part

Security is shared: use a strong, unique password (or single sign-on), don’t share your login, keep your recovery email current, and only grant team members the role their job actually needs.

Questions about any of this? Contact us at legal@xtremebook.com.

Security — Xtreme Book