← Back to getshepherd.co

Security Overview

Last updated: August 28, 2026

This page describes how Shepherd Software, LLC ("Shepherd") protects the data you connect to our continuous close accounting platform, including bank accounts, on-chain wallets, and the accounting systems you integrate with us. We've written it to be direct about both what's in place today and what's on our roadmap, since we'd rather you have an accurate picture than a polished one.

If you're evaluating Shepherd as a vendor and need more detail than what's here — a completed security questionnaire, a call with our team, or specifics not covered below — contact us at support@getshepherd.co.

1. Infrastructure & Hosting

Shepherd is hosted on Railway, with data persisted in a managed PostgreSQL database. We do not operate our own physical infrastructure. All traffic to Shepherd is served over HTTPS/TLS.

2. Multi-Tenancy & Data Isolation

Shepherd is a multi-tenant application. Every organization's data — wallets, transactions, chart of accounts, integration connections, and audit history — is scoped by an internal organization identifier and enforced at the database query level, so one customer's data is never returned in another customer's requests.

3. Authentication & Access Control

4. Encryption

All data in transit — between your browser and Shepherd, and between Shepherd and every third-party service it calls — is encrypted via TLS, with certificate verification enforced.

Data at rest: Our production database is hosted on infrastructure that provides disk-level encryption at rest. Application-level encryption of specific sensitive fields (for example, stored third-party integration credentials) is not yet implemented — this is on our near-term roadmap, and we're glad to discuss timeline and priority directly.

5. Sub-processors

Shepherd uses the following third-party services to operate. Each receives only the data necessary for its specific function.

ProviderPurpose
RailwayApplication hosting and managed database infrastructure
PlaidBank account connections and transaction data
Intuit (QuickBooks Online)Accounting sync, only if you connect your QuickBooks account
XeroAccounting sync, only if you connect your Xero account
Bill.comAccounts payable/receivable sync, only if you connect your Bill.com account
Anthropic / GoogleAI-assisted transaction classification suggestions
CoinGeckoPublic market pricing data for digital assets (no account or personal data is shared)

See our Privacy Policy for how data is shared with these providers.

6. Data Retention & Deletion

Data is retained for as long as your account is active. On account closure, data is deleted or anonymized within a reasonable period, except where we're required to retain it for legal, tax, audit, or regulatory purposes. You can disconnect any individual bank, wallet, or integration connection at any time from within the app.

7. Compliance

Shepherd does not currently hold a SOC 2 report or other third-party security certification. We're an early-stage company and treat this as a priority as we grow with larger customers — we're happy to walk through our current controls in detail and discuss certification timeline as part of a vendor review.

8. Vulnerability Reporting

If you believe you've found a security vulnerability in Shepherd, please report it to support@getshepherd.co. We take all reports seriously and will respond promptly.

9. Questions

Shepherd Software, LLC
support@getshepherd.co