Security is in June's DNA.
Security has been part of June from day one, not a feature added later. The founder comes from a Big 4 audit background, where security was not a checkbox but the whole job. That mindset shapes every product decision here: security is always, and will always be, top of mind.
How your data is protected
Encryption at rest
Your QuickBooks tokens are encrypted with AES-256-GCM before they touch our database. No one at June, including engineers, can read them in the clear.
Two-factor authentication
TOTP-based MFA available on every account. Add any authenticator app (Google, 1Password, Authy) in under a minute.
Managed authentication
Auth is handled by Supabase, on SOC 2 Type 2 infrastructure. We don't roll our own login flow, so we don't own its bugs either.
QuickBooks stays read-only
June only ever reads from QuickBooks. Every call the product makes to Intuit is a read, so nothing in your books is created, edited, or deleted by us. Intuit grants a single accounting permission that also permits writing; we do not use it.
Row-level isolation
Every row of client data is walled off with database-level policies. One firm cannot query another firm's data, even if a bug tried to let it.
Least-privilege access
Internal access is granted per-need, per-user, and logged. No blanket admin accounts, no shared credentials.
Have a security question?
Report an issue or ask a question. We answer every security inquiry personally.
