Security and access control
Financial information requires disciplined access and control.
Running your finance function means working inside your accounting system, your bank, your payroll provider, and your payment tools. This page describes how we handle that access.
What follows are operating practices, not certifications. We publish what we actually do—nothing more.
How we operate
Eleven practices we work by.
They apply to every engagement, and they are reviewed again as your systems and responsibilities change.
Least-privilege access
People are given access to the systems and records their responsibilities actually require, and nothing beyond that.
Role-based access where supported
When a system offers defined roles, we assign access by role rather than handing out broad administrative rights.
Multifactor authentication
We enable multifactor authentication on the financial systems we work in wherever the system supports it.
Approval controls
Bills, payments, expenses, and other financial actions follow agreed approval thresholds, and your leadership keeps the approval authority.
Documented financial workflows
Recurring financial work is written down with defined steps and a named owner, so control does not depend on one person’s memory.
Audit history where supported
Where a system records who changed what and when, we leave that history intact and use it when reviewing exceptions.
Secure credential practices
Credentials are kept in a password manager rather than in spreadsheets, email, or chat, and are updated when responsibilities change.
No shared banking credentials
We do not ask for or work from a shared bank login; access is granted individually through your bank’s own user permissions.
Vendor-change verification
A change to a vendor’s bank details or remittance information is verified through a known contact method before any payment is released.
Client-fund separation
Your money stays in accounts your company owns and controls; we work inside those accounts under the permissions you grant.
Periodic access review
We review who has access to which system on a recurring basis and remove access that is no longer required.
What we claim—and what we do not
We describe only the controls and operating practices currently in place.
We do not claim SOC 2, ISO 27001, or other formal certifications unless and until they have been obtained and independently verified.
Organizations with specific due-diligence requirements can request additional information during the evaluation process.
For questions about a particular control, contact hello@everypennyllc.com.
Financial control starts with knowing who has access to what.
A Financial Control Review covers approvals, access, and ownership alongside close, cash, billing, and reporting.