Help centre

Security

Security and data protection

How we store your data, how we authenticate, and what to expect from us.

  • Data hosted in EU regions on Supabase / Postgres with strict row-level security.
  • OAuth tokens encrypted at rest. No password storage.
  • Magic link, SSO (Xero, Intuit), and passkey sign-in supported.
  • 6-year retention on margin scheme records, per HMRC requirements.
  • Audit log on every scheme action.

Passkeys

Manage passkeys at Settings → Passkeys: add a passkey (with an optional friendly name), rename or remove one. We won't let you delete your last remaining sign-in method, and we warn you if you're managing passkeys from a domain that doesn't match the one they were registered against.

Compliance tooling

Firms can handle Subject Access Requests, erasure, data exports and retention from the Compliance centre.

Found a vulnerability? Please email security@onesixth.app.

Was this helpful?

What changed

Related