SECURITY AND DATA PROTECTION POLICY
Scott's Add-Ins, LLC
Last Updated: August 2026
EXECUTIVE SUMMARY
Scott's Add-Ins is committed to protecting the confidentiality, integrity, and availability of customer data. This document outlines our comprehensive security measures, with particular emphasis on encryption protocols, access controls, and data protection practices. Our security approach is built on industry best practices and designed to safeguard sensitive financial and business information.
1. SECURITY PRINCIPLES
Our security program is based on the following principles:
● Confidentiality: Personal and financial data is protected from unauthorized disclosure
● Integrity: Data is protected from unauthorized modification or alteration
● Availability: Services and data are accessible when authorized users need them
● Accountability: All system access and changes are logged and monitored
● Continuous Improvement: Security measures are regularly reviewed and updated
2. DATA ENCRYPTION
2.1 ENCRYPTION IN TRANSIT
All data transmitted between user devices and Scott's Add-Ins services is encrypted using industry-standard 256-bit TLS or higher protocols. This encryption:
● Encrypts all communication channels including website, APIs, and add-in components
● Uses 256-bit encryption strength for maximum security
● Prevents unauthorized interception or eavesdropping of sensitive data
● Is verified through industry-recognized SSL/TLS certificates
2.2 ENCRYPTION AT REST
Data stored in our systems is encrypted using Advanced Encryption Standard (AES) with 256-bit encryption keys. This includes:
● Database encryption for all customer data
● File-level encryption for stored documents and backups
● Key management systems to protect encryption keys
● Secure deletion of data when no longer required
2.3 KEY MANAGEMENT
Encryption keys are managed according to industry best practices:
● Keys are stored securely using Hardware Security Modules (HSMs) or equivalent
● Access to keys is restricted to authorized personnel only
● Keys are rotated periodically according to security standards
● Backup keys are maintained in secure locations
3. ACCESS CONTROLS
3.1 AUTHENTICATION
We implement strong authentication mechanisms to verify user identity:
● Username and password authentication with minimum complexity requirements. The authentication is handled by your accounting software provider (ex. Xero)
● Support for multi-factor authentication (MFA) using authenticator apps or SMS, via your accounting software provider.
● OAuth 2.0 integration for secure third-party authentication
● Password reset mechanisms with identity verification via your accounting software provider.
3.2 AUTHORIZATION AND PERMISSIONS
Access is granted based on the principle of least privilege:
● Role-based access control (RBAC) defines who can access what data. We use the role you have established with your accounting software provider.
● Users only have access to data necessary for their role
● Administrative privileges are granted sparingly and monitored closely
● Access rights are reviewed regularly and revoked when no longer needed
3.3 CUSTOMER ACCOUNT SECURITY
Customers maintain control over their own account access:
● Customers can manage team member access and permissions within their account
● Customers can revoke access immediately through the account interface
● API tokens can be rotated and revoked as needed
● Login activity is visible in customer account audit logs
4. INFRASTRUCTURE SECURITY
4.1 SYSTEM ARCHITECTURE
Our infrastructure is designed with security as a core principle:
● Layered network architecture with multiple security perimeters
● Firewalls configured to allow only necessary network traffic
● Intrusion detection and prevention systems monitor for suspicious activity
● DDoS protection to maintain service availability
● Secure API design with rate limiting and request validation
4.2 SERVER SECURITY
Our servers are maintained with security best practices:
● Operating systems are kept current with security patches
● Software dependencies are regularly updated and monitored for vulnerabilities
● Unnecessary services are disabled to minimize attack surface
● Servers are hardened according to industry security standards
● Physical access to servers is restricted to authorized personnel only
4.3 CLOUD INFRASTRUCTURE
When using cloud providers, we select providers with strong security records and certifications. Customer data is:
● Encrypted before transmission to cloud providers
● Stored in isolated environments with proper access controls
● Replicated across multiple availability zones for redundancy
● Protected by the cloud provider's security measures
5. DATA BACKUPS AND DISASTER RECOVERY
5.1 BACKUP PROCEDURES
We maintain regular backups of customer data to protect against loss:
● Automated daily backups of all customer data
● Backups are encrypted using AES-256 encryption
● Multiple backup copies stored in geographically diverse locations
● Periodic restoration testing to verify backup integrity
5.2 DISASTER RECOVERY
We maintain disaster recovery procedures to minimize service interruption:
● Documented disaster recovery plan with defined recovery objectives
● Regular testing and updates to recovery procedures
● Redundant systems and failover capabilities
● Communication plan for notifying customers of incidents
6. VULNERABILITY MANAGEMENT
6.1 VULNERABILITY ASSESSMENT
We proactively identify and remediate security vulnerabilities:
● Regular automated vulnerability scanning of systems and applications
● Code scanning tools to detect vulnerabilities in custom software
● Penetration testing to identify security gaps
● Vulnerability tracking and prioritization by severity
6.2 PATCH MANAGEMENT
Security patches and updates are applied promptly:
● Critical vulnerabilities are patched within 48 hours
● Standard vulnerabilities are patched within 30 days
● Updates are tested before production deployment
7. INCIDENT RESPONSE
7.1 SECURITY INCIDENT PLAN
We maintain an incident response plan to address security incidents:
● Incident detection and alerting mechanisms
● Incident classification and severity assessment
● Containment and remediation procedures
● Communication procedures for affected customers
● Post-incident analysis and improvement
7.2 BREACH NOTIFICATION
If a security breach affecting customer data occurs, we will:
● Notify affected customers without undue delay
● Provide information necessary to meet legal notification requirements
● Conduct thorough investigation of the incident
● Implement measures to prevent recurrence
8. EMPLOYEE SECURITY
8.1 TRAINING AND AWARENESS
All personnel who handle customer data receive security training:
● Initial security training for all new employees
● Annual security refresher training
● Awareness campaigns on current security threats
● Incident-specific training following security events
8.2 ACCESS CONTROL FOR EMPLOYEES
Employee access to customer data is strictly controlled:
● Access is granted only for job-related purposes
● All access is logged and monitored
● Access is revoked immediately upon termination of employment
● Background checks are conducted for employees with data access
9. THIRD-PARTY AND VENDOR SECURITY
We carefully evaluate the security practices of third-party vendors and sub-processors:
● Vendors are assessed for security certifications and practices
● Contractual obligations require vendors to maintain adequate security
10. COMPLIANCE AND CERTIFICATIONS
Scott's Add-Ins is committed to maintaining compliance with applicable security and privacy regulations. We follow industry standards including:
● NIST Cybersecurity Framework principles
● ISO 27001 Information Security Management practices
● GDPR and CCPA compliance requirements
● Industry-specific security best practices
11. MONITORING AND LOGGING
11.1 SYSTEM MONITORING
We continuously monitor systems for security threats:
● Real-time monitoring for suspicious activity
● Intrusion detection system alerts
● Log analysis and correlation to identify patterns
● Automated alerts for policy violations
11.2 AUDIT LOGGING
All access to customer data is logged and retained:
● User login attempts and successful authentication
● Data access and modifications
● System and configuration changes
● Logs are retained for minimum 90 days
● Logs are protected from unauthorized access and modification
12. SECURE DEVELOPMENT PRACTICES
Security is integrated throughout our software development lifecycle:
● Security requirements are defined for all new features
● Code reviews include security evaluation
● Security testing is performed before release
● Third-party code and dependencies are evaluated for vulnerabilities
13. CUSTOMER RESPONSIBILITIES
While we implement comprehensive security measures, customers also have important responsibilities:
● Keep account credentials confidential and secure
● Use strong passwords and enable multi-factor authentication
● Maintain updated and secure devices and software
● Report suspected security incidents promptly
● Comply with data protection laws in their jurisdiction
14. CONTACT INFORMATION
For security concerns, questions, or to report a suspected security incident, contact:
Scott's Add-Ins, LLC Email: help@scottsaddins.com Website: www.scottsaddins.com
15. DOCUMENT UPDATES
This Security and Data Protection Policy will be reviewed and updated annually or as needed to reflect changes in our security practices or in response to emerging threats. Updates will be posted on our website.
IMPORTANT DISCLAIMER
This Security and Data Protection Policy has been prepared as a comprehensive framework for your business. While we have endeavored to describe current security practices, specific implementations may vary. This document should be reviewed by qualified information security professionals and legal counsel. We strongly recommend independent security audits and penetration testing. Scott's Add-Ins provides this policy for informational purposes and disclaims liability for any consequences arising from its use. No security document can guarantee complete protection against all threats.