Skip to main content

Security

How we protect your data

GreenBar builds local-first tools, so there is one security model, not two. Clearing runs entirely on your own computer. GreenBar stores none of your data. GreenBar AP Pay, our payables tool, is still in development and will run on your machine the same way. Here is how your data stays protected.

Available now

Clearing

Local-first desktop · available now

Clearing installs and runs on your own machine. GreenBar operates no cloud and stores none of your financial data, so most of what a cloud product has to defend simply isn't there to attack. What we protect instead is the integrity of your work — and your control over what, if anything, ever leaves your computer.

The close stays on your computer

Clearing keeps the close on your computer. On launch it checks greenbarsystems.com for an update. That call does not include your bank file, your ledger, or the rest of the close. If you have already saved a license key, Clearing also checks that key. It sends the key only, not the books. Every other outbound connection stays off until you turn it on: a bank link, QuickBooks or Xero, or a team sync endpoint you control.

Runs locally on Windows, macOS, and Linux. No GreenBar account. The only default call is the update check. A license check runs only when a key is already saved. Neither one carries financial data.
GreenBar runs no cloud of its own and stores none of your data. There is no shared model trained on your books; the learning stays on your machine, per client.

Tamper-evident sign-off

Clearing's value is a close you can prove. The record of who did what is protected so it can't be quietly rewritten after the fact.

Hash-chained history. Each workflow event is chained to the last with a SHA-256 hash. When a file opens, the chain is verified. If a signed-off period was altered, it is detectable.
Sealed at sign-off. Once a period is signed off it is sealed; any later change shows in the trail.

Roles and sign-in

Separation of duties. On a team, the preparer and the reviewer must be different people — the same person can't both prepare and approve.
Optional end-to-end encryption. When your team sets an organization passphrase, preparer and reviewer names and notes are encrypted so only your team can read them.
Local sign-in uses PBKDF2 password hashing. Two-factor authentication is not yet available.

Export safety

Exported spreadsheets escape cell contents against formula injection, so a crafted vendor name or memo line can't execute when the file is opened in Excel.
In development

GreenBar AP Pay

Local-first payables · in development

AP Pay is our payables tool, and it is still being built. Like Clearing, it will run on your own computer rather than as a hosted service. We are not publishing its security details yet — we would rather say nothing than describe controls that are still changing.

AP Pay has not shipped yet

There is no release date to share. When AP Pay ships, its security details will be published here alongside Clearing's.

Security questions

If your organization requires security documentation ahead of a purchasing decision, we can provide a completed security questionnaire and schedule a security review call. Reach us at support@greenbarsystems.com.

Get the one-page brief

A condensed summary of everything on this page: how Clearing runs locally, what stays on your machine, and how sign-off is kept tamper-evident. Formatted to forward to IT or compliance.

Or view it now, no email needed →

Responsible disclosure

If you believe you have found a security issue in Clearing, GreenBar AP Pay, or greenbarsystems.com, please report it to support@greenbarsystems.com. We will acknowledge your report within two business days. Please do not publicly disclose the issue before giving us a reasonable window to address it.

  • Do not access, modify, or delete data that is not yours.
  • Do not perform denial-of-service or automated scanning without prior authorization.

Last updated: July 2026. Questions? Email support@greenbarsystems.com.