Preekie Beyond limits
Request access

Security and control

A person signs off
on everything.

Preekie is built on the assumption that AI is sometimes wrong. Every control below exists so that being wrong is caught, visible and reversible — never quietly posted to a ledger.

Controls

Six areas, each verifiable.

Approval

Nobody approves by accident

  • Nothing is written to a ledger or handed for lodgement until a named person approves it.
  • Approval requires a fresh code from that person’s authenticator app at the moment of signing.
  • Anything tax-affecting can only be approved by a user flagged as a registered agent or an authorised officer.
  • Every approval is recorded with what the approver saw, and when.

Access

Least privilege, by default

  • Every user signs in with an authenticator app. There is no password-only route into the product.
  • Users hold specific capabilities — prepare, review, approve, lodge — not blanket access.
  • Our support team cannot see client financial data unless an account administrator grants access for a limited time, and every view is logged.
  • Contacts outside your organisation never get a login. They act on single-use links that expire and are protected by a PIN.

The ledger

Only the engine writes

  • The AI proposes. A separate deterministic engine does the arithmetic and performs every write.
  • Before anything is written: balances, period lock dates, tax codes and duplicates are checked, and the record is confirmed unchanged since it was read.
  • Every write is confirmed by reading it back, and can be reversed. Nothing is ever deleted.
  • Ledger credentials are held in a managed secret store that only the engine can reach.

Evidence

A record that survives the argument

  • Every read, proposal, decision, message and write is logged.
  • Each figure in a workpaper links to the transaction or document behind it.
  • Evidence packs are sealed at sign-off, showing the position at the moment of approval.
  • Changes to a contact’s email or mobile are notified to the old details, verified on the new ones, and held before they take effect.

Infrastructure

Australian, and locked down

  • Client data is held and processed in Australia, in Amazon Web Services’ Sydney region.
  • Data is encrypted with keys we control, and key deletion is blocked by organisation-level policy in production.
  • Separate environments for development, testing and production. Real client data exists only in production.
  • Threat detection and security monitoring run across every environment, with alerts to a named person.

Payments

We never touch the money

  • Preekie prepares payment batches and tells you what is due. A person releases every payment.
  • New or changed bank details are held until confirmed by someone other than the person who entered them.
  • Card details for your subscription go straight to Stripe and are never stored on our systems.

Certification

Built to SOC 2 controls.

Preekie is built to the SOC 2 control set for security, confidentiality and availability: infrastructure defined as code and reviewed before deployment, no long-lived credentials, immutable audit logging, tested backups, and organisation-level policies that block changes to those controls. Preekie is not yet SOC 2 certified. The report follows an observation period, and we will say so here when it is issued rather than before.

Australian privacy law applies to everything we hold. A Privacy Policy and Terms are being drafted and will be published before access opens.

Questions

Ask us anything specific.

Security questionnaires, data flow diagrams and hosting details are available on request during onboarding.

Sign in to Preekie

Enter your work email. You will be asked for a code from your authenticator app.

No account yet? Request access.