Trust and security
How Oak protects your financial data
What Oak does with company financial data, who can see it, how long it is kept and how to get it back or delete it. Where something is not yet in place, this page says so.
Each company is isolated
Every company sits in its own workspace. Access is checked on the server for every request and again in the database with row-level security, so one company’s figures, conversations and reports are never mixed with another’s, including within a multi-company Enterprise account.
What Oak keeps from a file
When you upload a bank or accounting export, Oak reads it on the server, keeps the figures it extracts (the period, totals, monthly movements and the largest income and cost lines) and a SHA-256 fingerprint of the file, and discards the original. Oak never asks you to type financial figures.
Sign-in and access
Sign-in uses email and password with an authenticator-app second factor; exporting or deleting an account requires it. Company access is enforced through owner, admin, analyst and viewer roles. Authorised company data and account exports remain available in Settings.
Encryption and hosting
Traffic is encrypted in transit with TLS. Data is stored with Supabase, which encrypts databases at rest, and the application runs on Vercel. Server credentials never reach the browser. Payments are handled on Stripe’s hosted pages; Oak never receives card numbers.
AI processing
When you ask Oak a question, the relevant figures for that company and the conversation are sent to Anthropic to write the answer. Anthropic’s commercial terms state that API inputs and outputs are not used to train its models by default. Answers support your decisions; they do not make them.
Export, retention and deletion
An owner can download a full export of a company’s data, or delete the company, from Settings at any time. Financial evidence, conversations, forecasts, decisions and actions are kept while the workspace is active and removed when it or the account is deleted. Operational records are kept for fixed periods: billing webhook records and usage counters for 90 days, delivered notifications for 30 days and security events for 365 days. Audit logs are proposed to be kept for the life of the relationship plus 12 months, subject to contract. Provider backups roll off on the provider’s schedule and are never restored for ordinary use after a deletion.
Certifications and security reviews
Oak does not currently hold SOC 2 or ISO 27001 certification. We will complete your security questionnaire and share our data-protection impact assessment and retention schedule on request: enterprise@oakmontkingsley.com.
Single sign-on
Single sign-on (SAML or OpenID Connect) is not self-serve today. Enterprise customers can request it, and we will confirm what is possible with your identity provider before any agreement: enterprise@oakmontkingsley.com.
Enterprise enquiries
Enterprise is arranged case by case for groups and finance teams running several companies: company-specific specialist conversations and controlled workspace access, with invoiced billing. To talk it through: enterprise@oakmontkingsley.com.
Contact
Questions about this document or the Oak service can be sent to info@oakmontkingsley.com.