Security at EXIZIP

This page describes how EXIZIP actually works. Every statement here reflects the current product architecture — nothing on this page is a certification or a legal claim.

How EXIZIP connects to QuickBooks Online

EXIZIP connects to QuickBooks Online through Intuit's official OAuth authorization flow. Your QuickBooks credentials are entered directly on Intuit's own login page — EXIZIP never sees or stores your QuickBooks username or password.

What access EXIZIP requires

EXIZIP requests QuickBooks Online accounting access to retrieve your invoice list and download invoice PDFs. It only ever reads data from QuickBooks — it does not create, modify, or delete anything in your QuickBooks company.

How exports are processed

Invoice PDFs and ZIP archives are fetched directly from QuickBooks and assembled inside your browser. Invoice content, PDF files, and ZIP archives are never uploaded to or stored on Stanrell's servers.

What information is stored

Stanrell's backend (api.stanrell.com) stores only what's needed to keep your QuickBooks connection authorized between sessions: an encrypted OAuth refresh token (AES-256-GCM) and minimal connection metadata. Session tokens and license keys are stored as one-way hashes, never in their original form. All communication with the backend happens over HTTPS.

Payments and billing

Subscription payments are processed by Stripe. Stanrell's own database stores your Stripe customer and subscription reference IDs, your email, and your plan — never your card number or other payment details, which Stripe handles directly.

Disconnecting QuickBooks

You can disconnect EXIZIP at any time from within the extension. Disconnecting requests token revocation directly from Intuit and deletes your connection record from Stanrell's backend.