Security
Security and data protection
How we store your data, how we authenticate, and what to expect from us.
- Data hosted in EU regions on Supabase / Postgres with strict row-level security.
- OAuth tokens encrypted at rest. No password storage.
- Magic link, SSO (Xero, Intuit), and passkey sign-in supported.
- 6-year retention on margin scheme records, per HMRC requirements.
- Audit log on every scheme action.
Passkeys
Manage passkeys at Settings → Passkeys: add a passkey (with an optional friendly name), rename or remove one. We won't let you delete your last remaining sign-in method, and we warn you if you're managing passkeys from a domain that doesn't match the one they were registered against.
Compliance tooling
Firms can handle Subject Access Requests, erasure, data exports and retention from the Compliance centre.
Found a vulnerability? Please email security@onesixth.app.
Was this helpful?