June Analytics
ENFR
Security & Trust

Security is in June's DNA.

Security has been part of June from day one, not a feature added later. The founder comes from a Big 4 audit background, where security was not a checkbox but the whole job. That mindset shapes every product decision here: security is always, and will always be, top of mind.

How your data is protected

Encryption at rest

Your QuickBooks tokens are encrypted with AES-256-GCM before they touch our database. No one at June, including engineers, can read them in the clear.

Two-factor authentication

TOTP-based MFA available on every account. Add any authenticator app (Google, 1Password, Authy) in under a minute.

Managed authentication

Auth is handled by Supabase, on SOC 2 Type 2 infrastructure. We don't roll our own login flow, so we don't own its bugs either.

QuickBooks stays read-only

June only ever reads from QuickBooks. Every call the product makes to Intuit is a read, so nothing in your books is created, edited, or deleted by us. Intuit grants a single accounting permission that also permits writing; we do not use it.

Row-level isolation

Every row of client data is walled off with database-level policies. One firm cannot query another firm's data, even if a bug tried to let it.

Least-privilege access

Internal access is granted per-need, per-user, and logged. No blanket admin accounts, no shared credentials.

Have a security question?

Report an issue or ask a question. We answer every security inquiry personally.