Your company’s cloud account
Where the work happens, in the region you choose, for example Switzerland.
- Your workflows and their schedules
- The safe with your access keys
- The gatekeeper and its log
- Your dashboard and run history
Security & data
A tool that reads your accounting and your bank deserves hard questions. Here is what runs where, who holds which keys, and what never happens without you.
What runs where
Most of the work happens in a cloud account that belongs to your company. Your AI sits outside it, and so do we.
Where the work happens, in the region you choose, for example Switzerland.
Builds and adjusts the workflows when you ask. Works on the data a task needs, never on your keys.
Sets everything up and keeps it running, with the access you grant and can withdraw.
Illustrative examples. Logos are trademarks of their owners.
The gatekeeper
Workflows never hold the real keys to your bank or software. They ask for one by name. The gatekeeper checks the request, adds the real key on the way out, and writes it down.
“Read the ledger from bexio, with the bexio key.” It only knows the key’s name.
Is bexio on your list? Is this a payment that needs your OK? Anything else is blocked.
The real key comes out of the safe for that one call, then goes back.
The workflow gets the data. Never the key.
Illustrative examples. Logos are trademarks of their owners.
The commitments
Every payment a workflow prepares waits in your dashboard until someone on your team approves it. It then goes to your e-banking, where you sign it with your usual rights. A workflow can prepare a payment; it can never sign one.
Access is granted tool by tool, with the narrowest rights each workflow needs. Writing anything takes your explicit OK.
The gatekeeper only talks to the tools on your list. Anything else is blocked and logged.
Which workflow, which tool, what, when, and the result. You can read the log and export it at any time.
Every access can be withdrawn from the tool itself, your bank or bexio, without asking us.
Workflows, history and documentation stay in your cloud account. Nothing to hand back, nothing held hostage.
About AI, honestlySome workflows use AI for one step, such as reading a PDF receipt. That step goes to the provider you chose, through the gatekeeper, and it’s logged. The checks themselves follow fixed rules: the same lines give the same answer every time.
We sign an NDA before the free check, and a data processing agreement under the Swiss FADP and the GDPR before any setup. Send us your vendor security questionnaire: we’ll fill it in.
✓ NDA✓ Data processing agreement✓ Your questionnaire
Only during setup and support, with access you grant, and every look is logged like any other call. Once you’re live, we don’t keep a copy of your data on our side.
There’s no cloud account of yours yet at that stage, so we work from your read-only access or your export. It’s used for that check only, and deleted within 30 days of the walkthrough; we confirm the deletion in writing. If a step uses AI, such as reading PDF receipts, we tell you which provider before you send anything.
No. Your AI never holds the keys to your bank. Workflows prepare payments; a person on your team approves them, then signs them in your e-banking, as today.
It stops, logs why, and tells you and us by email. Nothing is retried in a way that could pay or send something twice.
In your own cloud account, in the region you choose, for example Switzerland. The data a task sends to Claude or ChatGPT is processed by that provider, under your agreement with them.
Everything stays in your account and keeps running if you want it to. We hand over the documentation and withdraw our own access.
To start
Every line: receipt, VAT code, account. Under NDA, findings in 2 working days. It starts with a 20-minute call.