Effective September 4, 2026
Your books, your customer and vendor details, and your payment activity are sensitive. Here’s a plain description of how Xtreme Book protects them — not a marketing checklist, an honest account of what’s actually in place today.
Xtreme Book is multi-tenant: many organizations share the same application, each with its own isolated data. Every request is scoped to the signed-in user’s organization at the database query level — there is no code path in the app that lets one organization’s data be read or written by another.
Within an organization, four roles — Owner, Accountant, Supervisor, and Staff — govern what each team member can see and do, from full financial and settings access down to day-to-day transaction entry. An organization’s Owner controls who holds which role.
Xtreme Book keeps an audit log of who created, edited, voided, or deleted significant records, and when — visible to your organization under Accounting > Audit Trail. Login activity, including any platform-support access described below, is also logged.
Card and Mobile Money payment details are handled entirely by Flutterwave, a licensed payment service provider — Xtreme Book never receives or stores full card numbers, mobile money PINs, or other sensitive payment credentials. We only store the resulting transaction reference, amount, and status.
A small number of authorized Xtreme Book staff can access the Super Admin area to provide support, investigate abuse, or fix an account issue. Every such action — including impersonating a user to troubleshoot on their behalf — is written to a separate, tamper-evident admin audit log distinct from your organization’s own audit trail.
Our database is backed up regularly by our hosting provider so that data can be restored in the event of an infrastructure failure. See our Terms of Service for our current availability commitment.
If you believe you’ve found a security vulnerability in Xtreme Book, please report it to security@xtremebook.com before disclosing it publicly. Give us a reasonable chance to investigate and fix it, and don’t access, modify, or delete data that isn’t yours while testing. We’ll acknowledge your report and keep you updated as we work on it.
Security is shared: use a strong, unique password (or single sign-on), don’t share your login, keep your recovery email current, and only grant team members the role their job actually needs.
Questions about any of this? Contact us at legal@xtremebook.com.