AccountMade

Trust & security

Security and Data Handling

How AccountMade handles approved sources, claim plans, reviewer decisions, buyer-ready exports, retention, access control, and procurement review questions.

Effective: August 25, 2026

1. Scope and boundary

AccountMade is a multi-tenant hosted business service operated by The Plain Works Co.,Ltd. This overview describes the current control approach; it is not a certification, audit report, warranty of invulnerability, or promise that every control applies identically to every beta feature.

We protect the hosted application, managed infrastructure, service accounts, and operational access under our control. Customers protect their endpoints, identities, connected systems, source accuracy, sharing choices, and exported data.

2. Access and tenant controls

AccountMade uses managed authentication, workspace roles, authorization checks, tenant identifiers, protected administrative access, and least-privilege practices. Customers must promptly remove former personnel, protect credentials and tokens, and review public or bearer links.

3. Data and secrets

Network traffic uses TLS. Core providers supply encryption at rest for managed databases and object storage. Integration credentials and service secrets are kept in managed secret stores or protected application storage and are not intentionally written to analytics. Logs and errors are filtered to reduce Customer Content and credentials, although diagnostic events may contain limited context needed to investigate a fault.

4. AI safeguards

AI features use approved commercial OpenAI and paid Gemini APIs. AccountMade sends only the context needed for the requested operation, does not use Customer Content to train general-purpose models, disables provider storage where supported, and limits standard provider abuse-monitoring retention to 30 days unless verified zero retention applies. Restricted data must not be submitted. AI output requires human review.

5. Public sharing and integrations

Private workspace authorization does not protect content that a customer deliberately publishes through a public or bearer link. Customers must verify content and access settings before sharing. Connected CRMs and document systems operate under customer-approved scopes; third-party permissions and destination security remain the customer's responsibility.

6. Operations

We use structured logging, rate limits, error and availability monitoring, dependency review, backups, deployment controls, incident procedures, vendor review, and access review appropriate to a lean SaaS operator. Security and authentication logs are normally retained 90 days. Deletion and backup periods are described in the Privacy Policy.

7. Incident response

We investigate suspected incidents, contain affected systems, preserve relevant evidence, remediate, and provide legally required notices. DPA customers receive notice without undue delay after confirmation of a reportable Customer Personal Data breach.

8. Vulnerability reporting

Send a concise report to hello@accountmade.com, including affected URL or component, reproduction steps, impact, and a safe proof of concept. Do not access other customers' data, persist access, disrupt service, extort, or publicly disclose a suspected issue before we have a reasonable opportunity to respond. We do not currently operate a paid bug-bounty program.

9. Assurance

AccountMade does not claim SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP, or similar certification unless a current written report expressly says so. Security questionnaires and reasonable enterprise review requests may be sent to hello@accountmade.com or legal@accountmade.com.

10. Contact

Security: hello@accountmade.com Privacy and DPA: legal@accountmade.com