Security, without the badge wall

You are about to give a piece of software access to the mailbox your business runs on. That deserves a straight answer about what it can and cannot do, rather than a page of logos. Here is how access works, what we store, and how to take it away.

OAuth only, never passwords

You authenticate directly with Google, Microsoft, Intuit or Xero. ZapBooks never receives, requests or stores a password for any connected account, and every connection can be revoked from the provider's own security settings.

Read-only mailbox access

The mailbox permission ZapBooks requests is read-only. It cannot send, move, modify or delete mail. If you scope the connection to a single label or folder, nothing outside it is examined.

Encrypted in transit and at rest

All traffic uses TLS. Documents and extracted data are encrypted at rest by our storage providers. Access to production systems is limited to personnel who need it to operate or support the service.

No money movement

ZapBooks does not hold funds, initiate payments or connect to your bank accounts. The blast radius of a ZapBooks compromise does not include your money leaving your account.

What we store, and for how long

DataRetention
Invoice documents processedWhile your account is active, then 90 days after cancellation
Extracted invoice dataWhile your account is active, then 90 days after cancellation
Messages not identified as invoicesNot stored
Email or accounting passwordsNever collected
Card detailsHeld by the payment processor, never by ZapBooks
Account and billing recordsAs long as tax and accounting rules require

Full detail, including sub-processors and your rights under GDPR and CCPA, is in the privacy policy.

The control that matters more than ours

The dominant invoice fraud affecting small businesses is not a software breach. It is payment redirection: a genuine vendor, a genuine invoice format, changed bank details, usually following a compromised email account somewhere in the chain.

No extraction engine detects this, because the document is real. ZapBooks flags any invoice where vendor payment details differ from that vendor's previous invoice, and holds it. Verifying the change by phone, on a number you already hold rather than the one printed on the invoice, is the step that actually stops it.

More on designing those controls in how to build an invoice approval workflow.

Security questions

Connect it read-only and see for yourself

14-day trial, no credit card, and you can revoke mailbox access from your own Google or Microsoft account at any moment.

Read the privacy policy

14-day free trial. No credit card required.