themassis.com
Information Security Policy
This program is designed to meet or exceed the control objectives of the AICPA Trust Services Criteria for Security, NIST SP 800-53 / NIST CSF, and ISO/IEC 27002, and to satisfy the FTC Safeguards Rule (16 CFR Part 314), the Plaid Master Services Agreement, and the Plaid Developer Policy. Diligence copy: information-security-policy.pdf.
1. Policy statement
themassis splits Shopify payouts, drafts balanced QuickBooks Online journal entries through a clearing account, and holds exceptions for human review. A merchant may optionally connect a bank account through Plaid so deposits can be matched. Nothing risky posts without an authorized accountant’s approval.
Senior management commits: we will not collect bank login credentials; we will not sell customer data; we will not use customer books to train unrelated models or to advertise; we will notify Plaid of a Security Breach within 12 hours; we will dispose of data under the Data Retention and Disposal Policy. There is no unwritten exception to these rules.
2. Scope and roles
Applies to all systems, personnel, contractors, and subprocessors that handle company or customer information, including the application, Shopify, QuickBooks Online, Plaid, Stripe, endpoints, source code, secrets, End User Data, and exports. A Qualified Individual oversees the program (FTC Safeguards Rule § 314.4(a)). Merchants cannot post. Accountants review and post for assigned clients. Support access is ticket-scoped, logged, and revoked when the ticket closes.
3. Classification
| Class | Examples | Handling |
|---|---|---|
| Restricted | Plaid access tokens and item ids; Shopify/QBO OAuth tokens; password hashes; encryption keys; Plaid and Stripe secrets | Encrypt at rest and in transit. Never log, email, or commit. |
| Confidential — financial | Payouts, journal lines, mappings, Plaid transactions used to match deposits, posting audit logs | TLS; tenant and role isolation; no marketing or resale; dispose on schedule. |
| Confidential — personal | Email, name, store domain, support mail, auth IPs | Need-to-know; deletion and access rights honored. |
4. Plaid and End User Data
Never collected: bank login credentials, PINs, OTP/MFA codes, institution session cookies, or full card PAN/CVV.
After Plaid Link we exchange a public_token server-side for an access_token and item_id. Those values, plus the selected account id, are stored encrypted at rest (Fernet). Transaction data is requested only for the deposit account you selected. On disconnect, account closure, or irreparable item error, within 24 hours we call Plaid item/remove and delete encrypted tokens from the primary store.
End User Data is used solely to provide the requested reconciliation, prevent fraud on that connection, comply with law, and support a ticket you opened. No sale, no advertising, no AI training corpora. Employee access is need-to-know and logged.
Plaid Dashboard credentials, client_id, and secret are not published. Security events are reported to [email protected] within 12 hours of becoming aware of a Security Breach.
5. Access, encryption, application
- Least privilege and tenant isolation. Server-side sessions; opaque HttpOnly cookie.
- Passwords hashed with scrypt. Login rate limits. CSRF on state-changing requests.
- Same-day revocation on termination. Privileged access uses unique identities, MFA, and is logged.
- TLS 1.2+ in transit. Tokens encrypted at rest. Secrets not in git. Keys unique per environment and rotated at least annually.
- Financial posting cannot happen without an authorized human. Workstations that can reach production use disk encryption, auto-lock, current patches, and current anti-malware.
6. Logging, vendors, incidents
We log authentication, connect/disconnect, payout processing, approve/reject/post, and privileged access — not secrets. Posting audit logs are kept 7 years.
Vendors that receive End User Data or tokens: Shopify, Intuit, Plaid, Stripe, and cloud/email. They are contracted and reviewed. themassis remains responsible for subprocessors.
Report incidents immediately to [email protected]. Triage as soon as practicable, not to exceed 12 hours. Contain first (rotate secrets, revoke sessions and tokens). Notify Plaid within 12 hours for a Security Breach involving Plaid data. Notify affected customers without unreasonable delay.
This page does not claim SOC 2 or ISO 27001 unless a current report is linked here. Reports: [email protected].
7. Contact
themassis · themassis.com · [email protected] · [email protected]