Trust

Security

How your books are kept separate, and what the software will and will not do on its own.

One business cannot see another

Every business has its own set of books. Each request is scoped to the business it was made against, so a person with access to one brand does not see another — including brands inside the same holding group, which keep separate ledgers even while the group can see a consolidated view.

Open a business you have not been given access to and the app says so plainly rather than showing you an empty screen, so a stale bookmark never looks like lost data.

Nothing posts without a person

Scanned documents are read automatically, but reading is all that happens on its own. Every capture arrives in Checkpoint as a draft for a bookkeeper to check against the original document and approve. Until somebody posts it, nothing has reached the ledger. Where the reading is uncertain the software says so and makes reviewing — not posting — the obvious next step.

A posted entry is never quietly rewritten

Correcting something that has already been posted does not edit it. The original is reversed and a fresh draft opens for the correction, so the original entry, its reversal and the replacement all remain on the books. An auditor can see what was recorded, that it was changed, and what it became.

Drafts, which have never touched the ledger, can be discarded outright — nothing leaves your ledgers when they are.

People see only their part of the job

Access is granted per business and per role. Someone whose job is scanning paperwork in gets the capture screen and nothing else — not the ledger, not the reports, not the team. An accountant runs the books but need not be able to manage who else has access. Permissions can be tailored per person beyond the role they were given.

Closed periods stay closed

Once a month is reconciled it can be locked. A soft close stops staff posting into it while the owner or accountant can still make adjustments; a hard close freezes it completely. Either can be reopened deliberately, by someone with the authority to do it.

Shared reports expire

A report sent to a client goes as a link rather than an attachment that lives forever in a chat. Those links stop working after seven days, and any of them can be revoked immediately from Shared links, which lists every one you have sent and whether it is still live.

Documents and the AI that reads them

Captured documents are sent to an AI provider to be read. What that means, what is sent, and who is the controller of a firm's client data is set out in the Privacy Policy — the disclosure matters enough to belong there in full rather than be summarised here.

Telling us about a problem

If you believe you have found a security problem, write to support@alevatebooks.com with enough detail to reproduce it. Please report it to us before disclosing it elsewhere, and give us a reasonable chance to fix it.

What we do once we know is written down rather than improvised: our incident response policy sets out who acts, in what order, and who gets told when.

Alevate Books is operated by UKPACKAGES LIMITED, a company registered in England and Wales, 12 Constance Street, London E16 2DQ, United Kingdom.

← Back to Alevate Books