Security
What MatchRail stores, who processes it, and how to report a vulnerability. Accounts exist on this product.
What it stores
- Your account: the email address you sign in with, and the ledger you connect
- Your purchase orders, bills and payments as read from that ledger, and the goods receipts you record here — neither QuickBooks Online nor Xero has a receipt entity, which is the gap this product exists to fill
- Every match the agent ran, every variance it found and every correction you approved, because that record is what makes the kill window provable rather than asserted
- Anonymous usage analytics — page views and clicks. Form inputs are masked in session recordings
Who processes it
- Supabase: authentication and the database holding your orders, receipts, bills and match history.
- Intuit QuickBooks: one of the two ledgers a book is read from and a correction you approved is written back to.
- Xero: the other, under exactly the access you granted.
- Stripe: reads the payments so a bill paid before its match passed is flagged rather than quietly closed, and takes your own subscription payment.
- PostHog: anonymous product analytics, proxied through this domain.
- Vercel: serves this site and holds its access logs.
Also true of this product
- The plans are PRO at $5/month. There is no free tier — the live demo at /demo is the free surface, and it needs no account and no card.
- It does not move money. There is no payment run and no payout rail in this product.
- The matcher is arithmetic, not a language model. Nothing about whether two documents agree is decided by a model.
- Nothing is written back to your ledger without you approving that specific correction, and it refuses to post a figure that changed after you approved it.
- Every action the agent takes is written to an append-only ledger with the evidence it acted on, including the ones nobody looks at. That record is what makes the kill window provable rather than asserted.
- There is no password on this product. Sign-in is a link sent to your email address, so there is nothing to reuse, leak or reset badly.
- Your data is scoped to your organisation at the database level, not only in the interface.
Reporting a vulnerability
Write to security@thecompound.tech. The machine-readable version of this line is at /.well-known/security.txt.