This page describes how Shepherd Software, LLC ("Shepherd") protects the data you connect to our continuous close accounting platform, including bank accounts, on-chain wallets, and the accounting systems you integrate with us. We've written it to be direct about both what's in place today and what's on our roadmap, since we'd rather you have an accurate picture than a polished one.
If you're evaluating Shepherd as a vendor and need more detail than what's here — a completed security questionnaire, a call with our team, or specifics not covered below — contact us at support@getshepherd.co.
Shepherd is hosted on Railway, with data persisted in a managed PostgreSQL database. We do not operate our own physical infrastructure. All traffic to Shepherd is served over HTTPS/TLS.
Shepherd is a multi-tenant application. Every organization's data — wallets, transactions, chart of accounts, integration connections, and audit history — is scoped by an internal organization identifier and enforced at the database query level, so one customer's data is never returned in another customer's requests.
All data in transit — between your browser and Shepherd, and between Shepherd and every third-party service it calls — is encrypted via TLS, with certificate verification enforced.
Shepherd uses the following third-party services to operate. Each receives only the data necessary for its specific function.
| Provider | Purpose |
|---|---|
| Railway | Application hosting and managed database infrastructure |
| Plaid | Bank account connections and transaction data |
| Intuit (QuickBooks Online) | Accounting sync, only if you connect your QuickBooks account |
| Xero | Accounting sync, only if you connect your Xero account |
| Bill.com | Accounts payable/receivable sync, only if you connect your Bill.com account |
| Anthropic / Google | AI-assisted transaction classification suggestions |
| CoinGecko | Public market pricing data for digital assets (no account or personal data is shared) |
See our Privacy Policy for how data is shared with these providers.
Data is retained for as long as your account is active. On account closure, data is deleted or anonymized within a reasonable period, except where we're required to retain it for legal, tax, audit, or regulatory purposes. You can disconnect any individual bank, wallet, or integration connection at any time from within the app.
Shepherd does not currently hold a SOC 2 report or other third-party security certification. We're an early-stage company and treat this as a priority as we grow with larger customers — we're happy to walk through our current controls in detail and discuss certification timeline as part of a vendor review.
If you believe you've found a security vulnerability in Shepherd, please report it to support@getshepherd.co. We take all reports seriously and will respond promptly.
Shepherd Software, LLC
support@getshepherd.co