Skip to content

Security

How your data is handled

Plain answers to what a controller asks before sending financial exports. Main does not claim any certification; where something is still being put in place, this page says so.

Main is not a CPA firm and does not perform audits, reviews, compilations or other attest services; it provides financial data reconciliation and exception analysis to support your team and your CPA.

What we collect and why

Only the project financial exports you choose to send (change orders, schedules of values, payment applications, receivables, retainage) and the names and emails of the people you invite. They are used only to reconcile your revenue and prepare drafts for you.

Where it is stored

In a dedicated database separated per organization by row-level security, and in object storage where each organization’s files are encrypted with that organization’s own key. Original files are kept unchanged so every number can be traced back.

Who can see it

People you invite, with the role you give them. Main staff see a customer’s data only by opening a logged access session with a stated reason; your organization owner can see every access in the activity log.

Protections

  • Invite-only accounts with mandatory two-factor authentication
  • Encryption in transit (TLS) and at rest
  • Tenant isolation enforced in the application and again in the database, tested on every release
  • Short-lived signed download links
  • An append-only activity log of logins, exports, approvals, role changes and deletions
  • Customer data is not used to train AI models. Where an AI model is used (column-mapping suggestions, plain-English summaries, drafting), it receives only what that task needs and never computes an amount

Retention and deletion

Raw uploaded files are scheduled for deletion after the engagement; full retention details are being finalized. You can export all your data or delete your organization’s data at any time; deletion ends with a deletion certificate.

NDA and incidents

A mutual NDA is available before you send anything. Report a security concern through the contact page; it reaches a person at Main.

Subprocessors

ProviderPurpose
NetlifyWebsite and application hosting
Managed PostgreSQL provider (to be named before the first customer)Application database
Amazon Web ServicesEncrypted file storage and key management
AnthropicAI model for mapping suggestions, summaries and drafts (no amounts computed by the model)
StripeBilling
Transactional email provider (to be named before launch)Invitations and notifications to your registered users
Plausible AnalyticsCookie-free website analytics on public pages

This list will be updated before any provider receives customer data.