CashLinxHome

Security

Effective July 19, 2026

CashLinx handles financial and, where enabled, banking data, so security is a first-class part of the product rather than an afterthought. This page summarizes our current posture. It describes controls in place today and is not a certification.

Tenant isolation

CashLinx is multi-tenant with strict separation between practices and between a practice's clients. Every tenant table carries a practice identifier, and client-scoped data carries a client identifier. Access is enforced in the database with default-deny row level security: a request sees no rows unless a policy explicitly grants access. Practice staff see only their own practice's data, and a client-portal user sees only their own company's data.

Access control

  • Two separate audiences, practice staff and client-portal users, with distinct roles and least-privilege rights.
  • Privileged operations run through narrowly scoped server-side paths, never from the browser.
  • Authorization is checked on the caller's session before any elevated action, and the database enforces the same boundaries again.

Data protection

  • Data is encrypted in transit using industry-standard TLS.
  • Connection secrets for accounting and banking systems are stored encrypted.
  • Data is encrypted at rest by our infrastructure providers. See our Subprocessors page.

Auditing and integrity

Sensitive actions are recorded in an append-oriented audit log. Records are generally disabled or archived rather than hard-deleted, so history and an audit trail are preserved. Writing back to a client's accounting system is gated behind a client approval and a CPA review.

Banking data

Banking connectivity is handled through a dedicated provider and is enabled per tenant only when the feature is turned on. Until then, no banking data is collected. A full security review is completed before any real banking connection or external client goes live.

Infrastructure

The Service runs on managed cloud infrastructure with a hardened database and hosting layer. We keep dependencies current and follow secure development practices, including type-safe boundaries and input validation at every trust boundary.

Responsible disclosure

If you believe you have found a security vulnerability, please report it to security@mycashlinx.com. We appreciate responsible disclosure and will work with you to understand and address valid reports promptly. Please do not access data that is not yours or degrade the Service while testing.

Contact

Security questions: security@mycashlinx.com.

CashLinx, under the SuiteLinx umbrella.
PrivacyTermsCookiesSecurityContactAll policies