Heesab
Back to dashboard

Heesab Security Summary

Effective: June 17, 2026

This Security Summary describes Heesab's current pilot security posture. It is written for pilot customers and Intuit production-readiness review. It should be read with the Privacy Policy, Terms of Service, and Data Retention Policy.

Heesab is operated by Basha Holdings LLC d/b/a Heesab.

Security contact: [email protected]

Support contact: [email protected]

Product Scope

Heesab receives invoice emails, parses invoice documents, maps vendors and accounts, and posts approved or trusted routine invoices to QuickBooks Online as Bills. Heesab does not run payroll, make payments, move money, file taxes, or provide accounting advice.

Access Control

Current controls include:

Before broader client self-serve access, Heesab still plans to complete the sandbox/production split

decision, run the final security check, and add client authenticator-app MFA as a future option.

QuickBooks Security

Current controls include:

For the v1 invoice-to-Bill workflow, Heesab is intended to request the QuickBooks Online Accounting scope.

Auto-Post Guardrails

Heesab is designed so routine trusted invoices can auto-post only when guardrails are met. Current guardrails include:

production testing showed QBO did not actually void the Bill.

Unknown, unmapped, incomplete, low-confidence, duplicate, unusual, paused, or over-limit items stay in review instead of auto-posting.

Audit Trail

Heesab records important operational events, including invoice receipt, queueing, mapping, edits, approvals, rejections, auto-post decisions, QuickBooks posts, errors, tenant status changes, and connection events.

Audit logs are database-enforced immutable against update, delete, and truncate. This supports accountability for actions taken in customer books.

Data Security

Current controls include:

No system can guarantee absolute security. Customers should report suspected unauthorized access, incorrect posting, misdirected invoice forwarding, or token exposure to [email protected].

Incident Response

If Heesab suspects unauthorized access, incorrect posting, token exposure, or misdirected invoice data, the expected pilot response is:

The internal operator runbook for these steps is `docs/INCIDENT_RESPONSE_RUNBOOK.md`.

Providers

Heesab currently uses third-party providers to operate the service, including:

Provider use may change as the product matures.