Security you can verify.
Automation does not remove accountability. Future Perfect LLC remains the security owner and final escalation point, while accounting controls and customer review constrain what agents may do.
Isolation
Each customer receives a separate append-only ledger process, data volume, credentials, encryption key, backups, and audit-root pin.
Least authority
Models never choose tenant, actor, role, credentials, or command templates. The server binds identity and permits only narrow accounting workflows.
Close controls
Duplicates, unresolved exceptions, staged activity, a non-zero reconciliation difference, or a backdated write block the close.
Recovery
Encrypted off-host snapshots, separate root pins, restore tests, and reproducible reports make recovery testable rather than assumed.
Agent boundary
Agents may interpret merchant descriptions, apply approved patterns, draft owner questions, and explain reports without advice. They may not call the immutable store directly, create arbitrary journals, change accounting basis, waive a reconciliation difference, close a blocked period, send money, file taxes, or hold unrestricted shell access in the write path.
Protected onboarding
The control plane verifies the access token, maps that verified identity to a tenant and actor on the server, and rejects tenant or actor fields from browser input. The public eligibility form collects no bank credentials or financial records.
Reporting a concern
Email kyle@futureperfect.work to report a suspected security issue. Do not include credentials, statements, account numbers, or other financial records in email.