Data protection
- The DPA sets obligations for appropriate technical and organisational measures.
- Confirm encryption coverage, credential access and key management in the deployment security schedule.
- Use synthetic or properly anonymised data in sandbox; protect production credentials separately.
Ledger integrity
- Accounting workflows include balanced journals and correction history; validate your mappings and outputs.
- Review the supported posting and reversal behavior for your integration.
- Idempotency applies according to the endpoint contract, including key scope and retry requirements.
Access and activity
- Configure user roles, client scopes and tenant access for your deployment.
- Verify signed webhook payloads using the documented procedure where supported.
- Confirm activity coverage, export formats and retention required for your audit needs.
Deployment and recovery
- Hosting, subprocessors and processing locations must be identified for the applicable service.
- Hosted and customer-managed deployments have different operational responsibilities.
- Confirm backup, restore and incident procedures in the security schedule before production processing.
- Availability targets are distinct from commitments in an agreed SLA.
Data rights and processing
- Customer Data rights and permitted processing are defined in the Terms and DPA.
- Supported exports and post-termination access follow the agreed service and exit terms.
- The DPA and deployment-specific subprocessor and security schedules form the processing package.
The architecture describes product behavior; deployment evidence and the agreed security schedule establish the applicable controls and responsibilities. Explore the architecture.