Skip to content
Security & Compliance Dossier · 2025

The paperwork your procurement team will ask for, written down plainly.

SOC 2 Type II certified since 2022. GDPR and CCPA-aligned. A read-only posture toward your source ledgers, encryption at rest and in transit, and the first 1-click audit trail accepted by Big Four diligence teams. This page is the dossier — not the marketing.

Certifications held
SOC 2 Type II · GDPR · CCPA
Source posture
Read-only OAuth · no write access
Trust portal
status.ebitnow.com ↗
Certifications & Control Frameworks

Every line item a security questionnaire asks for, on a single page.

EBITnow maintains the formal certifications and operational controls that procurement, IT security, and outside counsel diligence teams require before a finance vendor touches the books. Each tile below is a citable fact, not a marketing claim.

S2

SOC 2 Type II — held since 2022

Annual audit by an independent AICPA-accredited firm covering Security, Availability, and Confidentiality trust service criteria. The current report covers the 12-month observation window ending Q4 2024 with zero exceptions noted. Reports are released under NDA through the trust portal.

  • Type II (not Type III) — operating effectiveness tested over time
  • Clean opinion, no qualified findings in the 2024 report
  • Report available to prospects and customers under mutual NDA
EU

GDPR & UK GDPR aligned

Data Processing Addendum, Standard Contractual Clauses, and EU-West regional residency available on request. Customers retain a documented right to access, portability, and erasure of source data.

CA

CCPA & CPRA aligned

Service-provider language, opt-out signals honored, and a published privacy notice that lists every sub-processor with name and purpose. No sale of personal information, full stop.

E2

Encryption, end to end

AES-256 at rest, TLS 1.3 in transit, customer-managed keys available on the Enterprise plan. Secrets are stored in a dedicated KMS with per-environment rotation policies and quarterly key ceremony reviews.

R0

Read-only source posture

Every integration uses OAuth scopes explicitly scoped to read access. EBITnow has no write path into your ledger, billing, or payroll systems — enforced at the integration layer, audited annually.

A1

1-click audit trail — accepted by Big Four diligence teams

The first real-time EBITDA platform to ship a single-click audit trail export that has been independently accepted by Big Four diligence teams during M&A and audit cycles. Every metric in the dashboard is reproducible to the source transaction — no hidden joins, no spreadsheets behind the curtain.

  • Immutable, hash-chained event log for every calculation
  • PDF + CSV export with provenance metadata embedded
  • Used in due diligence by Big Four teams on named 2024 engagements
Operational Reliability Record

We publish the numbers ourselves. So should any vendor wiring into your books.

EBITnow operates a public trust portal at status.ebitnow.com showing live uptime, latency p95, refresh cadence, and a 90-day incident history. The figures below are the 2024 calendar-year audited record; the portal shows what is true right now.

99.98%
Measured uptime, 2024 calendar year
Audited across the full 12-month window on the production cluster.
15min
EBITDA refresh cadence
672 refreshes per 7-day week against the median F100 close of 7 days.
312ms
Median dashboard load (p50)
p95 of 740ms across all 27 production regions in Q4 2024.
live
status.ebitnow.com
Real-time uptime, latency, refresh metrics, and the full incident history. No login required.
Open the trust portal
Data Handling Disclosure

What we read, what we store, what we never touch.

EBITnow reads from your bookkeeping, billing, and payroll systems over scoped OAuth connections, computes a continuously refreshed EBITDA view, and writes nothing back. Below is the plain-language record of how customer financial data is handled — written for a CFO and a security reviewer to read together without translation.

What is read from source systems

EBITnow pulls a defined set of objects — chart of accounts, posted journal entries, invoices, subscriptions, payroll runs — over read-only OAuth scopes. We pull the minimum fields needed to compute EBITDA on a cash basis: revenue, deferred revenue movement, COGS, and the relevant operating expense categories.

EBITnow does not read unstructured fields, customer PII, employee compensation records, or banking credentials. The platform is not a general ledger — it is a purpose-built EBITDA engine, and the read scope is constrained accordingly.

What is stored, and where

Computed values are stored in our production Postgres cluster encrypted at rest with AES-256. Customer-specific secrets are held in a dedicated KMS with per-environment key rotation. By default, US-East (Virginia); EU-West (Ireland) regional residency is available on the Enterprise plan.

Source credentials are never stored in plaintext, never logged in application logs, and are scoped to read-only at the integration layer — there is no write path into your source systems.

Retention and deletion

Computed EBITDA history is retained for the life of the customer contract plus 30 days. On contract end, all customer data is hard-deleted from primary storage within 30 days and from backups within 90 days. A deletion certificate is issued on request.

A documented sub-processor list is published on the security portal and updated within 10 business days of any change. Notification is sent to all customers on file.

Who can access your data

Access is least-privilege, MFA-enforced, and logged. Production access requires a hardware-backed key and a documented change ticket. Fewer than 12 named EBITnow engineers have any path to customer data, and access is reviewed quarterly.

EBITnow does not provide tax, audit, or advisory opinions. Computed figures are presented on a cash basis and are intended as an internal management view — they are not a substitute for audited financial statements or formal tax advice.

Frequently Asked — By Procurement

The questions security questionnaires and diligence calls ask before anyone signs.

If you need a formal answer that does not appear below, write to [email protected] and a human on the security team will respond within one business day.

Do you support SAML SSO and SCIM provisioning?

Yes — SAML 2.0 SSO with Okta, Azure AD, Google Workspace, JumpCloud, and any IdP that speaks the standard. SCIM 2.0 user provisioning is included on the Growth and Enterprise plans. Just-in-time provisioning and group-based role mapping are both supported.

How is the audit trail exported, and who has accepted it?

The 1-click audit trail generates a PDF and a CSV from a single button in the dashboard. Every computed metric is reproducible to the source transaction, with provenance metadata embedded. The export has been independently accepted by Big Four diligence teams during 2024 M&A and audit engagements.

What is your breach notification commitment?

Customers are notified within 72 hours of a confirmed security incident that affects their data, per our contractual SLA and GDPR Article 33. The trust portal at status.ebitnow.com publishes a post-incident summary for any user-impacting event within 5 business days of resolution.

What happens to our data when the contract ends?

On contract end, you can export a full archive of your computed EBITDA history and audit trail for 30 days. After 30 days, customer data is hard-deleted from primary storage; backups rotate out within 90 days. A signed deletion certificate is provided on request.

How do you control employee access to customer data?

Access is least-privilege and MFA-enforced, with hardware-backed keys required for production. Fewer than 12 named engineers have any path to customer data. All access is logged in an immutable audit log and reviewed quarterly by the security steering committee.

How do I request the latest SOC 2 Type II report?

Email [email protected] with your company name and the requesting party's email. Reports are released under mutual NDA within one business day. Current customers can also pull the latest report directly from the trust portal.

Compliance confirmed · Next step: see it running on your books

Twenty minutes. Your live EBITDA, on your stack.

Bring a QuickBooks, Xero, NetSuite, Stripe, or Gusto login to the call — we'll connect it, show you the EBITDA view refreshing every 15 minutes, and hand you a board-ready PDF before you hang up.

  • SOC 2 Type II since 2022
  • Read-only OAuth · 71 ledgers & billing systems
  • 2,140+ SaaS finance teams
  • 41-day average customer ROI payback