Outlane
Security
Last updated: September 17, 2026
Outlane holds your ledger, your forecast and sometimes your payroll. This page describes how the app protects them today, and what we are still building. It does not describe anything we have not built.
Signing in
- There are no passwords to steal, reuse or reset. You sign in with a link or a 6-digit code sent to your email.
- The link and code work once, for 15 minutes. The code only works in the browser that asked for it, and five wrong tries use it up.
- Sign-in emails are limited per email address and per network address, to slow down anyone trying to flood an inbox or guess codes.
- We store only hashes of sign-in links, codes and session tokens, not the values themselves.
- Your session is a cookie that scripts on the page cannot read. It lasts 30 days from when you last used Outlane. Signing out ends it on our side too.
Who can see and change what
- Every workspace has roles: Admin, CFO, Controller, Senior accountant, Staff accountant, Head of sales, Head of marketing, Head of HR and Viewer, plus any roles the workspace adds.
- Admin always has full access and cannot be changed. Admins can edit what every other role can do.
- Every page and every change is checked against your role before it runs.
- By default, team heads see only their own page, not the financial statements.
- A workspace cannot be left without someone who can administer it. A person removed from a workspace loses access to it at once.
- Every change to people, roles and what a role can do is logged, with who made it and when. Admins can download an access report as a CSV file: one row per person, what they can do, who added them and when they last signed in.
Requests and pages
- A change is accepted only if it comes from Outlane’s own pages. A request sent from another website is refused.
- Signed-in pages are marked so that browsers and proxies do not store a copy.
- Everything except the sign-in pages, shared report links and a health check requires you to be signed in.
Connections to your accounting system
- QuickBooks Online connects through Intuit’s own sign-in, so we never see your Intuit password. Intuit does not offer a read-only permission, so Outlane asks for its standard accounting permission and only ever reads.
- NetSuite connects with token-based credentials. Outlane tests them before use and pulls data only when someone in your workspace asks.
- Tokens and credentials are encrypted with AES-256-GCM before they are saved, using a key kept outside the database. A copy of the database alone does not reveal them.
- Disconnecting QuickBooks asks Intuit to end the connection and deletes the tokens. Removing a NetSuite connection deletes its credentials.
- Only people with admin access can connect or disconnect an accounting system.
Sharing reports
- Only a published report can be shared. A report with a failing check cannot be published.
- Each link holds a long random token. We keep a hash of it for lookup, and an encrypted copy so the sender can copy the link again.
- Links expire. The default is 90 days, and the sender can choose from 1 to 365 days. A link can be revoked at any time.
- Every open is logged, with a hashed network address, so the sender can see whether and when the report was opened.
- A report can also be downloaded as a single file that opens only with a password. The file is encrypted with AES-256-GCM, using a key derived from the password with PBKDF2 (600,000 iterations). The password must be at least 12 characters, and we never store it.
AI
- AI only suggests. A person confirms every mapping, driver and scenario change before it is used.
- Sorting accounts and suggesting drivers never send amounts to the AI provider.
- The assistant sends the figures it needs to answer, with the provider’s storage turned off.
- AI keys are kept in the app’s server settings, never in the database or the browser.
- Outlane can run with AI switched off entirely.
Our privacy policy lists exactly what each AI task sends.
Hosting and data
- The app and its data are hosted in the United States on Fly.io (Ashburn, Virginia), on an encrypted disk. The app is served only over HTTPS.
- The database is backed up every day: 14 days on the server’s disk and 30 days in separate encrypted storage. Every week the newest copy is downloaded and checked to open intact.
- This marketing website is a separate app and holds no workspace data.
- There are no analytics, advertising or tracking scripts in the app.
- Each customer has a retention period, 7 years unless we agree another. Imported files past it are deleted automatically every day.
- Admins can download everything their workspace holds in one file, and delete the workspace and all its data themselves, at any time. Deleted data leaves backups within 30 days.
Activity and history
- Every change, upload, approval, download, share-link view and sign-in is recorded: who, when, from which network address, and whether it was allowed. Admins can view and export it. It is kept 400 days.
- The record says what was done, never the figures or text involved.
- Every saved version of a company’s drivers and account mapping is kept with who saved it, and an earlier version can be restored.
- Requests are rate limited, upload sizes are capped, and every response carries standard security headers.
Subprocessors
Companies that process workspace data for us, and what they receive:
- Fly.io (United States): hosts the app and its database, and stores backups (through its storage partner Tigris Data). Everything in a workspace.
- Resend (United States): sends sign-in and notification emails. Email addresses, names, and the text of those emails.
- OpenAI (United States): only when a workspace uses AI features, and only what each AI task sends, as listed in our privacy policy. Sent with storage off; not used to train models.
Systems you connect, such as QuickBooks, Stripe, App Store Connect or Google Play, are your own accounts: Outlane reads from them with the access you approve, and you can disconnect them at any time.
What we do not have yet
Outlane has no security certifications or independent audits yet, such as SOC 2. We describe only what is built, and will say so here when that changes.
Reporting a security issue
If you think you have found a security problem in Outlane, email hello@outlane.ai. Please include enough detail for us to reproduce it, and give us a chance to fix it before telling anyone else. We will reply.