Financial, banking and payroll information requires more than a password.

CUNNTAS has been designed around the principle that security, accountability and the integrity of financial records must be fundamental parts of the platform, not optional features added to a more expensive subscription.

The name CUNNTAS is pronounced “KOON-tas”. It comes from the Scottish Gaelic word cunntas, meaning “account”, “accounts”, “accounting” or “reckoning” — a name that reflects both the purpose of the platform and its Scottish identity.

Every CUNNTAS Organisation benefits from the same core security architecture, including mandatory Two-Factor Authentication, controlled User access, secure banking integration, audit records, protected support access and internal platform-integrity monitoring.

1. Mandatory Two-Factor Authentication

Two-Factor Authentication is mandatory for every CUNNTAS User.

After entering their email address and password, Users must verify their identity using a compatible Authenticator App.

CUNNTAS uses an established authentication standard rather than requiring a particular manufacturer's application. Users can therefore use Google Authenticator, Microsoft Authenticator or another compatible Authenticator App.

The Authenticator credential identifies both CUNNTAS and the User's email address, helping the User distinguish the CUNNTAS account from other credentials stored in the same application.

Two-Factor Authentication cannot simply be switched off by a User.

2. Trusted Browsers

A User who successfully completes Two-Factor Authentication may choose to Trust this browser for 30 days.

This creates a secure, browser-specific credential allowing that User to sign in on the trusted browser without repeatedly entering an Authenticator code during the 30-day period.

Trusting a browser does not remove Two-Factor Authentication from the account. Another browser or device must still be authenticated independently.

Users should only trust browsers on devices under their control and should never use this facility on a public or shared computer.

Each User's trusted-browser authorisation is maintained separately, even where several CUNNTAS accounts are used through the same browser.

3. Recovery Codes

When Two-Factor Authentication is established, CUNNTAS provides single-use Recovery Codes.

These allow a User to recover access if the Authenticator App or device becomes unavailable.

Recovery Codes must be kept securely. Each code can be used only once and should be protected in the same way as other important authentication credentials.

CUNNTAS stores Recovery Codes in a protected form rather than retaining the usable codes as ordinary readable account information.

4. Secure Sessions

CUNNTAS maintains authenticated sessions so that Users can work within the platform without repeatedly signing in while carrying out normal accounting and administrative tasks.

Where a browser has been explicitly trusted, CUNNTAS can use that trusted-browser credential to restore an authenticated session if the ordinary browser session has expired unexpectedly.

An explicit Sign Out ends the active session.

This distinction allows CUNNTAS to provide practical session continuity without treating a deliberate Sign Out as an accidental interruption.

5. Individual User Accounts

CUNNTAS separates the User from the Organisation.

Every person accessing CUNNTAS should use their own User Account rather than sharing credentials between employees, directors or advisers.

A User can then be authorised to access one or more Organisations through that single identity.

This approach improves both security and accountability because activity can be associated with the individual User responsible for it.

6. Organisation Access and Permissions

Access to an Organisation does not automatically provide unrestricted access to every CUNNTAS function.

The platform is designed around controlled relationships between Users and Organisations, allowing permissions and responsibilities to be assigned according to the User's role.

A User must not access another Organisation's information unless authorised to do so.

This separation is particularly important where a single CUNNTAS User works with several companies or where an Organisation has several Users.

7. Controlled Support Access

Technical support sometimes requires access to information that cannot be adequately diagnosed from outside an Organisation's workspace.

CUNNTAS does not treat that requirement as justification for unrestricted permanent support access.

The platform includes a Protected Support Access system through which temporary access can be authorised for a support session.

Support access is based upon User approval, controlled access and recorded activity.

This allows assistance to be provided while preserving the Organisation's control over access to its information.

8. Banking Security

CUNNTAS is designed to obtain banking information through supported banking and Open Banking services.

Users do not provide their online banking passwords directly to CUNNTAS in order for the platform to obtain banking information.

Authentication with a financial institution takes place through the relevant banking or Open Banking authorisation process.

CUNNTAS receives the information made available through the authorised connection and uses it for the banking, reconciliation, bookkeeping and accounting functions selected by the Organisation.

9. Protecting the Integrity of Bank Information

A bank statement is evidence of activity recorded by a financial institution. It should not become an editable document simply because it has been imported into accounting software.

For that reason, CUNNTAS is designed so that banking information obtained through a connected banking service is not freely rewritten by Users.

Users work with the accounting treatment of banking transactions rather than altering the underlying bank information to make it agree with the accounts.

This helps preserve the distinction between what the bank reported and how the Organisation accounted for it.

10. Accounting Integrity

CUNNTAS is built around double-entry accounting.

Transactions created through different areas of the platform ultimately form part of the Organisation's accounting record.

Sales, purchases, payments, banking, payroll and VAT therefore do not exist merely as unrelated pieces of information.

Maintaining those relationships allows CUNNTAS to preserve the accounting consequences of transactions and provide a financial record capable of review.

11. Permanent Financial Documents

Invoices and Credit Notes created as permanent financial documents form part of the Organisation's transaction and billing history.

Financial records should not silently change simply because an earlier document becomes inconvenient.

Where a financial transaction requires correction, appropriate accounting processes — including Credit Notes, reversals or subsequent entries where applicable — preserve the relationship between the original transaction and its correction.

This provides a clearer and more accountable financial history than simply replacing evidence of what previously occurred.

12. Audit and Event Records

CUNNTAS records important User and system activity.

Audit and event records help establish what occurred, when it occurred and, where applicable, which User or system process was responsible.

This is particularly important where several Users have access to an Organisation.

Auditability provides both a security function and an accounting-integrity function: important changes should be capable of explanation.

13. Interface Standards and Structural Integrity

CUNNTAS contains internal tools designed to monitor the integrity of the application itself.

The Interface Standards system examines important relationships between application components, including database structures, routes, views and services.

This allows certain structural inconsistencies to be detected before the affected page or function is encountered by an ordinary User.

Database compatibility, routing integrity, view integrity and service integrity can therefore be assessed as part of platform administration rather than relying solely upon Users discovering errors during normal work.

14. Controlled System Standards

Important platform-wide values should not be repeatedly recreated by individual Organisations.

CUNNTAS uses controlled system and reference data for functions where consistency is necessary, including accounting frameworks, VAT treatments and other platform standards.

This reduces the risk of individual Users inadvertently creating conflicting values for information that should be consistently applied.

Changes to important global settings can also be subject to administrative control and audit history.

15. Help and Warning Systems

Security and integrity also depend upon Users understanding what they are doing.

CUNNTAS therefore distinguishes between information that requires explanation and information that requires caution.

Context-sensitive Help (?) facilities explain terminology, fields and functions.

Separate Warning (!) facilities identify important consequences, security considerations or other matters requiring particular attention.

These systems provide guidance at the point where a decision is being made without unnecessarily cluttering the interface.

16. Secure Payment Processing

Subscription payments may be processed through supported external payment providers.

CUNNTAS retains the billing and accounting information necessary to administer subscriptions, invoices, Credit Notes and payments without requiring complete payment-card information to be stored within the CUNNTAS accounting platform where the payment provider performs that function.

Payment-provider credentials and sensitive platform secrets are not intended to be exposed as ordinary readable settings within User or Administrator screens.

17. Infrastructure and Communications

CUNNTAS uses encrypted HTTPS communications to protect information transmitted between the User's browser and the platform.

Production infrastructure is designed to separate and protect important platform components, including application services, databases, stored information, secrets, logging and other operational resources.

Development and production environments are maintained separately so that development work does not require routine modification of the live customer environment.

18. Protecting Sensitive Configuration

Passwords, authentication secrets, payment credentials and other sensitive configuration information should not be stored or displayed as ordinary application content.

CUNNTAS separates sensitive credentials from normal platform settings and uses protected configuration and secrets-management mechanisms where appropriate.

Administrator screens can therefore indicate whether a service is configured without needing to reveal the underlying secret to every administrator who can view the settings page.

19. Monitoring and Auditability

Security is not a single login event.

CUNNTAS records operational and security-relevant information that can assist with identifying failures, unusual activity and important system events.

Platform health, communications failures, application events and structural findings can be reviewed through Administration functions.

This gives CUNNTAS administrators visibility into the operation of the platform rather than treating infrastructure and application behaviour as an invisible process.

20. Data Protection

CUNNTAS processes personal information in accordance with its Privacy Policy and applicable data-protection requirements.

Organisations remain responsible for ensuring that information they place within CUNNTAS has been obtained and is being processed lawfully.

Access to information is limited according to the User's authorised relationship with the relevant Organisation and the functions available to that User.

21. Security Is a Shared Responsibility

CUNNTAS provides security controls, but Users also have responsibilities.

Users should maintain secure devices, protect their passwords, Authenticator credentials and Recovery Codes, review access to their Organisations and report suspected unauthorised activity promptly.

Users should never approve an authentication or support-access request they do not recognise.

A security system is strongest when the platform and its Users both treat access to financial information seriously.

22. Security Without Making CUNNTAS Difficult to Use

Strong security should protect legitimate Users rather than continually obstruct them.

Mandatory Two-Factor Authentication establishes a strong second factor, while trusted browsers reduce unnecessary repeated challenges on devices the User controls.

Individual User identities improve accountability while allowing one User to manage several authorised Organisations.

Controlled Support Access permits technical assistance without establishing unrestricted permanent access.

The objective throughout CUNNTAS is to combine security with practical financial administration.

23. Platform Integrity by Design

CUNNTAS treats security and accounting integrity as related principles.

A secure system must protect who can access information.

An accountable system must record who performed important actions.

An accounting system must preserve the relationship between transactions and their financial consequences.

A reliable platform must also be capable of identifying problems within its own application structure.

CUNNTAS has therefore been designed around all four requirements:

  • Authentication.
  • Authorisation.
  • Auditability.
  • Financial and platform integrity.

These protections form part of the CUNNTAS platform for every subscribing Organisation.

They are not premium security features and do not require a more expensive subscription.

Security and integrity are part of the £30 per Organisation per month, plus VAT, CUNNTAS service.

Last Updated: 10 August 2026