№ 14Compliance dossier · Security

Security and compliance.

Your Xero or QuickBooks connection is scoped to what we actually need to draft and post vouchers — nothing more. Connection tokens are encrypted at rest, voucher PDFs sit behind private expiring links, and each company's data lives in its own tenant. The detail below is for anyone who wants to know exactly what we can and can't see.

§ 01What we read · what we don't

✓   What we read

  1. 01Transactions or purchases on the Xero org or QuickBooks company you connect — to draft and post vouchers.
  2. 02Contacts (Xero) or vendors (QuickBooks) on the company you connect — to identify shareholders.
  3. 03Account settings — to know which dividend account and bank to use.
  4. 04Your registered office address from Companies House (separately, by company number, in every mode).

✕   What we don't

  1. 01Payroll data, employee records, or salary information.
  2. 02Advisor permissions or anything outside the listed Xero or QuickBooks scopes.
  3. 03Bank feeds, statements, or live banking connections.
  4. 04Other clients' data — every Xero org or QuickBooks company is its own tenant on our side.
  5. 05Nothing at all, in documents-only mode — there is no accounting connection to read.

§ 02Scopes requested

These are the scopes you grant when you connect a Xero organisation to Dividendly. Xero is moving from broad transaction scopes to granular ones during 2026 — your consent screen may differ depending on when you authorised the connection. We keep access as narrow as supports the workflows you actually use.

QuickBooks Online asks for a single scope. It covers reading accounts, vendors and past purchases, and posting the dividend Purchase with its attachment — no payroll, no payments. Intuit reviewed our security questionnaire before issuing production keys. Refresh tokens last around 100 days; we track expiry and prompt you to reconnect before it lapses. You can also revoke access from Intuit's connected apps at any time.

§ 03Encryption and storage

Tokens encrypted, documents private.

Your Xero and QuickBooks access and refresh tokens — and the in-flight OAuth session — are encrypted at rest with AES-256-GCM, with separate keys per environment held outside the database. Losing a key would invalidate connections, not expose data. Generated voucher PDFs are stored in private storage and served only through short-lived signed URLs — no public links.

Application roles are default-deny: a signed-in user gets access only to what has been explicitly granted, and every data access is filtered to their own organisation. We don't claim more than that — voucher amounts and shareholder names are not encrypted field by field.

§ 04Tenant isolation

Each company's data stays in its own tenant.

Directors, vouchers, settings, and workflow records are all scoped per organisation. When you switch from one company to another, you switch tenants — there's no shared layer where a voucher from one client could appear in another's ledger.

§ 05UK voucher fields

Vouchers we generate carry the fields HMRC expects.

  1. 01Date dividend is paid
  2. 02Company name and company registration number
  3. 03Shareholder name receiving dividend
  4. 04Dividend amount per share and total dividend amount
  5. 05Financial period and tax year context

Have a security question?

Write to us.

For specifics about Xero or QuickBooks scopes, encryption, multi-tenant data isolation, compliance evidence, or anything else this page doesn't cover. We'll come back the same business day.

hello@dividendly.co.uk