Overview
Desktop Accounting API, operated by NMAJOR STUDIOS LLC, a Wyoming limited liability company, moves accounting data between your servers and your customers' QuickBooks Desktop. We keep that data for as short a time as the product allows, protect every credential with one-way hashing or encryption, and isolate each customer's data by project and connection. This page describes the measures in place. Annex 2 of our Data Processing Agreement contains the same measures in contract form.
How data flows
- Your server calls api.desktopaccountingapi.com over HTTPS with a secret key.
- We queue the request for the End User's connection.
- The QuickBooks Web Connector on the End User's computer polls qbwc.desktopaccountingapi.com over HTTPS, receives the request and returns QuickBooks' response.
- We return the response to your server, and to your webhook endpoint if you subscribed.
The Web Connector only makes outbound HTTPS requests, so nothing connects into your customer's network. We do not ship or install Windows software. The platform runs on Cloudflare's serverless infrastructure, and we run no servers of our own for product data. Our subprocessor page lists every provider involved.
Encryption
- In transit: every public endpoint requires HTTPS. The Web Connector endpoint accepts TLS 1.2 or newer, and the website sends HTTP Strict Transport Security.
- At rest: our infrastructure provider encrypts the databases and object storage that hold request data.
- Application-level: webhook signing secrets are encrypted with AES-256-GCM. A Web Connector password is held encrypted only during setup and deleted when setup completes or expires.
Credentials
| Credential | Protection |
|---|---|
| API secret keys | Shown once, then stored only as an HMAC-SHA-256 hash with a server-side secret. We cannot show a key again. Revoked keys stop working within 30 seconds. |
| Web Connector passwords | Generated per installation and stored only as a keyed hash after setup. |
| Setup links | Limited to one End User and to between 15 minutes and 7 days. On first load the secret moves into a secure cookie and leaves the address bar. |
| Webhook signing secrets | Encrypted at rest. Each delivery is signed with HMAC-SHA-256 under the Standard Webhooks format, and rotation keeps the previous secret valid for 24 hours. |
| Dashboard accounts | Verified email, passwords of at least 12 characters stored with a salted memory-hard hash, rate-limited sign-in, 7-day sessions checked against the database on every request, and session revocation on password reset. |
We never receive QuickBooks login passwords. End Users sign in to QuickBooks on their own computers.
Isolation and access
- A secret key reaches only its own project. Every query on customer data is filtered by that project, and requests for another project's resources return "not found" without revealing that they exist.
- Each connection has its own queue and storage. Internal calls verify the expected project and connection, and stored objects are namespaced by both and never exposed by URL.
- Test and production projects are separate, with separate keys.
- Dashboard roles separate owners, admins and members. Every dashboard action re-checks the caller's membership on the server.
- Production access is limited to NMajor Studios personnel who need it. Our internal support view cannot show secret keys, setup links, Web Connector passwords, End User email addresses or request bodies, and every lookup in it is audit-logged.
Data retention
We do not keep a copy of your customers' books. Automated jobs delete stored data on this schedule:
| Data | Kept for |
|---|---|
| Request and response bodies | 15 days after completion, or 24 hours after completion when payload capture is off |
| Request metadata: operation, status, timeline, timings, errors, QuickBooks status | 30 days |
| Cached pages for paginated lists | 1 day |
| Idempotency keys and stored responses | 7 days |
| Webhook events and delivery attempts | 30 days |
| Web Connector session records | 30 days after the session closes |
| End Users and connection details | Until you delete the End User |
Deleting an End User removes its connection and credentials immediately and its stored request data through a background deletion that retries until it completes, normally within 24 hours and never later than the 15-day expiry that applies to all stored request data. Our Web Connector configuration tells QuickBooks that personal data is not needed, so QuickBooks does not send Social Security numbers or full card numbers. The dashboard masks tax IDs, card, bank account and similar fields when it displays bodies.
Logging and monitoring
- Service logs record request IDs, operations, status and timings. They never contain authorization headers, API keys, Web Connector passwords, setup secrets, cookies or accounting bodies.
- Scheduled jobs, including data retention, report to independent monitoring that alerts us when a job fails or stops running.
- Our status page checks the API, Web Connector endpoint, setup flow, dashboard and documentation every five minutes and shows 90 days of history.
Application security
- Content Security Policies on every web surface allow only approved script sources, and inline code runs only by exact hash or per-request nonce.
- Rate limits apply to the API, failed authentication, sign-in, email links and website forms.
- Webhook deliveries refuse redirects and are blocked from private and internal network addresses.
- The API never accepts cookies or browser credentials. Cross-origin browser requests are allowed only from our documentation playground, which keeps any key you enter in memory only.
- Changes pass automated type checks, tests and builds, and platform changes deploy to a staging environment before production.
Payments
Polar, our merchant of record, handles checkout and payment details. Card numbers never reach our systems.
Compliance
Desktop Accounting API does not hold SOC 2, ISO 27001 or other third-party security certifications. Our Data Processing Agreement includes the GDPR Article 28 terms, the Standard Contractual Clauses and the UK Addendum, and applies automatically to every customer. We answer security questionnaires through our contact page.
Your responsibilities
- Keep secret keys on your servers or in a secret manager, never in browser or mobile code.
- Rotate keys when people leave or a key may have leaked.
- Send setup links only to the customer they are for.
- Verify webhook signatures and reject old timestamps.
- Show customers
userFacingMessagerather thanmessage, which can contain identifiers meant for you.
Vulnerability disclosure
We welcome reports from security researchers. To report a vulnerability, use our contact form or live chat and start your message with "Security report". Describe the issue, the affected URL or endpoint, and the steps to reproduce it. Leave out credentials, exploit payloads and any customer data in the first message; we will arrange a way to receive sensitive details. Our security.txt file points here.
In scope
- www.desktopaccountingapi.com, including /docs and /dashboard
- api.desktopaccountingapi.com, qbwc.desktopaccountingapi.com and connect.desktopaccountingapi.com
- status.desktopaccountingapi.com
- Our published SDKs
Out of scope
- Denial-of-service and load testing, spam, and social engineering of our staff or customers
- Physical attacks, and attacks on End User computers or QuickBooks itself
- Third-party services, including Cloudflare, Polar and Intuit products; report those to the vendor
- Reports from automated scanners without a demonstrated impact, missing best-practice headers without an exploit, and self-XSS
Rules
- Test only against accounts and test projects you own. Never access, change or delete data that belongs to others; if you reach it by accident, stop and tell us.
- Do not degrade the Services for other users.
- Give us a reasonable time to fix the issue before you disclose it publicly.
If you follow these rules in good faith, we will not pursue legal action against you for your research, and we will treat your testing as authorized under our Terms of Service. We will acknowledge your report, keep you informed as we investigate, and credit you if you wish. We do not run a paid bug bounty.