TenkeyBridge

Security & Data Handling

Last updated: October 5, 2026

TenkeyBridge lets an app you use read from and write to your QuickBooks company file. This page explains, in plain language, how that connection works and how your accounting data is handled along the way. For the legal terms, see our Privacy Policy and Data Processing Addendum.

How the connection works

Your QuickBooks reaches out to us; we never reach into it. The QuickBooks Web Connector, a tool that works with QuickBooks Desktop and Enterprise, runs on the machine where QuickBooks runs and periodically makes an outbound, secure web (HTTPS) call to TenkeyBridge to ask whether there is any work to do. Our optional Windows agent works the same way: it only dials out.

  • No inbound ports, no VPN, no firewall openings. Nothing on the internet can connect to your QuickBooks machine through TenkeyBridge.
  • Works with hosted QuickBooks. The same outbound connection works from hosted QuickBooks desktops; we run in production on Rightworks today.
  • The Web Connector talks to QuickBooks locally, on the same machine.

Encryption

Your data is encrypted in transit on every network hop. We use TLS 1.2 or higher everywhere.

  • QuickBooks to us. The Web Connector connects to qbwc.tenkeybridge.com over HTTPS only. That address is served by an Amazon Web Services (CloudFront) edge with an Amazon-issued certificate and caching turned off.
  • Our edge to our servers. The edge forwards to our API at api.tenkeybridge.com over HTTPS only (TLS 1.2), and verifies our certificate on every connection.
  • Your app to us. api.tenkeybridge.com forces HTTPS.

To be upfront: this is not end-to-end encryption. TenkeyBridge has to read your data briefly in order to translate between the QuickBooks Online format your app speaks and the format QuickBooks Desktop understands. That happens in memory, as described below.

What we store, and what we never store

What we store

  • Account and organization details (names, emails, members)
  • Which company files are connected, and their connection status
  • Credentials we issue, kept only as one-way hashes (we cannot read them back)
  • Request logs: metadata such as time, status, and which company file, kept for 30 days
  • A transport log of message sizes and SHA-256 fingerprints (digests)

What we never store

  • The contents of your company file: customers, invoices, items, balances, anything
  • The data inside requests and responses
  • The raw QuickBooks messages (qbXML); only their size and fingerprint are logged
  • Values typed into a search (such as a customer name); query logs keep the shape of the search with the values removed

Your accounting data passes through our gateway only while a request is being served. It is processed in memory to translate it and is not written to any database or log. Our database (Neon Postgres) holds account and connection details, and Neon encrypts stored data at rest.

Who controls access

  • Your QuickBooks admin approves it. The first time the Web Connector connects, a QuickBooks administrator must authorize the app inside QuickBooks.
  • You can revoke it anytime.In QuickBooks, go to Preferences → Integrated Applications, or remove the app from the Web Connector.
  • One company file, one set of credentials. Each company file connects with its own username and password, delivered with a setup (.qwc) file. The password is never emailed.

Where data lives

Our servers and database are in the United States. Web Connector traffic reaches them through Amazon CloudFront's encrypted edge network, which caches nothing. The full list of companies that help us run the service, and what each one handles, is at tenkeybridge.com/subprocessors.

Retention

  • Request logs are deleted after 30 days.
  • Account and organization data is deleted within 30 days after an account is closed, or sooner if you ask.
  • Billing records are kept as long as tax and accounting law requires.

Certifications

We do not currently hold a third-party security certification such as SOC 2, and we won't imply otherwise. A signed Data Processing Addendum is available on request, along with a written security summary. Email legal@tenkeybridge.com.

Contact

For security or legal questions, or to request a signed DPA, email legal@tenkeybridge.com. For privacy requests, email privacy@tenkeybridge.com.