Security is more than encryption. It is control over who can see, decide, and act.
CharFlo combines technical access boundaries with accounting workflow controls. The system is designed to protect financial data and prevent automation from taking consequential action on its own.
Access has clear boundaries
Permission-based access
Every user sees only the information and actions they are authorized to access.
Private document storage
Original documents and working data use private storage rather than public file URLs.
Controlled intake
New uploads enter a controlled inbox for review before they join an accounting workflow.
Metadata-conscious logging
Operational logging is designed to keep financial content out of ordinary logs.
Accounting controls constrain automation
- Reconciliation, balances, totals, and statement construction use deterministic logic.
- Manual corrections and approved decisions outrank generated suggestions.
- Low-confidence items remain visible and are routed to questions or review.
- Client-facing outputs and consequential actions require human approval.
- The tax workflow does not autonomously calculate liability or file returns.
Bank connections, when enabled
Bank transaction intake depends on configuration and external provider approval. Where it is available, the connection is explicitly authorized and read-only. CharFlo does not initiate payments, transfers, or other money movement.
This page states the controls supported by the product architecture. It does not claim certifications or production capabilities that have not been independently verified.
Questions about your engagement?
Security requirements can vary with the documents, services, and systems involved. Ask the CharFlo team how the controls apply to your specific engagement.