theta advisory

Security

How Blink is built, hosted and controlled — and how to tell us if you find a problem with any of it.

Last updated 27 August 2026.

Hosting and encryption

  • Blink is hosted in Canada.
  • All traffic is TLS-encrypted. All data is encrypted at rest.
  • The database is not reachable from the public internet; it sits inside a private network and is reachable only by the application.
  • Secrets and connection strings live in a managed secret store, not in configuration files or source control.

Accounts and access

  • Sign-in is by Microsoft single sign-on or an email and password. Sessions expire after 30 minutes of inactivity and can be revoked centrally.
  • Each tenant’s data is isolated at the database level, not only in application code.
  • Credentials for your accounting system are stored as encrypted OAuth tokens. We never store your Xero or QuickBooks Online password.

Controls built into the product

  • Separation of duties. Preparation and approval are separate steps, and a user with the approver role cannot approve a journal or document they prepared. Every approval records who performed it, so the separation is verifiable in the audit trail rather than taken on trust.
  • Append-only audit trail. Every calculation, change, approval and posting is recorded. Each entry is hashed against its position in the sequence, and entries are copied to separate storage as they are written.
  • Nothing posts without approval. Only an approved journal can reach the general ledger.
  • Sign-off certificates. A signed-off document produces a verifiable certificate, and going stale re-opens it rather than silently passing.

Theta Advisory holds no SOC 2 or ISO 27001 certification, and no audit against either has been performed. The controls above were built with those frameworks' criteria in mind, which is not the same thing as being certified against them — if that changes, this page will say so plainly rather than implying it.

How we build

  • Dependencies are scanned on every change and on a recurring schedule, and vulnerable ones are patched on a timetable driven by severity.
  • Static analysis and secret scanning run on every change before it can merge.
  • Deployments are automated and reproducible; infrastructure is defined as code.
  • Production access is limited to named individuals and is audited.

Reporting a vulnerability

If you believe you have found a security issue, please tell us before telling anyone else. Email security@thetaadvisory.ca with enough detail to reproduce it. We will acknowledge within two business days and keep you updated until it is resolved.

We will not pursue legal action against anyone who reports an issue in good faith, gives us reasonable time to fix it, and does not access or modify other people’s data in the course of finding it. We do not currently run a paid bounty.

Evaluating Blink and need more detail than this page gives — backups, key management, incident response, access controls? Ask us. We answer security questions directly rather than publishing everything.