How your data is kept

How Osmuch keeps your data: separated from every other business, encrypted where it matters, two-step sign-in, an audit trail, nightly backups and a copy kept off the server.

Signing in

The door into your records, and what stops somebody else walking through it.

  • Two-step sign-in. Anyone can add a code from an authenticator app to their sign-in, with one-time recovery codes in case a phone is lost.
  • Passwords worth having. At least 12 characters. Common passwords, and ones built from your own email address or business name, are refused.
  • Guessing is slowed down. Sign-in attempts are rate limited, so nobody can try password after password against your account.
  • A lost phone signs out. Changing your password signs out every phone on your account at once, and deactivating an employee ends their session straight away.

Who can see what

Your team sees what their job needs, and you can see who did what.

  • Admin-only sections. Mark any section admin-only, or hide it from particular people, so pay, bank details and the accounts stay with the people who need them.
  • An audit trail. Admins can see who signed in and who changed what, kept for a year. Nobody can edit or delete it from inside Osmuch.
  • Hosted in the EU. Osmuch runs on a server in the EU, behind Cloudflare, and all traffic to and from it is encrypted over HTTPS.

Backups, and leaving

Your records are safe if something goes wrong, and yours to take with you.

  • Backed up every night. The whole database and every uploaded file are backed up nightly, with a copy kept away from the server.
  • Export whenever you like. Download your accounts as a spreadsheet or a CSV for any period, ready to hand to your accountant or keep for yourself.
  • Closing an account. An admin can close the whole organisation. There are 30 days to change your mind, and then everything is erased, files included.