Trust & security

Your clients' data, treated like your own

Lottie was built by accountants, for accountants — so security isn't a bolt-on. From a least-privilege Xero connection to a full audit trail and two-person approval, every part of the product is designed to keep you in control of what happens to your ledger.

Least-privilege Xero access Full audit trail Two-factor authentication UK GDPR • ICO registered
Xero connection

Connected with least privilege

Lottie asks Xero for only the permissions she needs to run your month-end — and nothing that lets her touch the rest of your ledger.

Official Xero OAuth

You authorise the connection inside Xero. Lottie never sees or stores your Xero password, and Xero shows you every permission before you approve it.

Reads only what she needs

Invoices and bills, your chart of accounts and trial balance, invoice attachments and the fixed-asset register where used — to build your registers.

Never edits your source data

Lottie only posts manual journals and their reversals. She never edits your invoices, bank transactions or contacts.

Disconnect anytime

Revoke access from Xero or disconnect in-app at any moment — the connection is yours to end whenever you like.

Posting governance

Nothing posts without your rules

Every journal that reaches Xero follows the controls you set — with a complete record of who did what.

Two-person approval

Turn on four-eyes review and no set-up or release journal posts until a second person approves it.

Full audit trail

Every create, amend, post, approval and reversal is logged with before/after detail and exportable activity reports.

You decide when it posts

Journals can post automatically on schedule or be held for review — the choice is set per practice.

Access & accounts

Strong account security

Sign-in and team access are protected by modern controls out of the box.

Two-factor authentication

TOTP authenticator-app 2FA is available to everyone and enforced for owner and admin roles; practices can require it for the whole team.

Role-based access

Admins manage the team; read-only reviewers can leave notes but can never edit, post or export financial data.

Hardened sign-in

A 12-character password policy, brute-force lockout and an inactivity auto-lock keep sessions safe.

Data separation

Your clients stay isolated

Multi-entity work never means mixed-up data.

Per-entity isolation

Each client organisation is kept separate, with its own chart of accounts and nominal-code classification — no cross-client bleed.

Reputable cloud infrastructure

Lottie runs on reputable, professionally managed cloud infrastructure.

Encrypted in transit

All data moving between your browser, Lottie and Xero travels over encrypted HTTPS (TLS).

Your data rights

You own your data

UK GDPR & the ICO

WorkWithLottie is registered with the UK's Information Commissioner's Office (ICO), and a Data Processing Agreement (DPA) is available on request.

Deletion on your terms

You can request full deletion of your data at any time. Data is removed within 30 days of account closure.

We never sell your data

Your practice and client data is used only to provide the service to you — it is never sold or shared for marketing.

Security questions?

Reviewing Lottie for your practice or need our DPA? We're happy to walk through anything.

hello@workwithlottie.com

Ready to put month-end on autopilot?

7-day free trial · no card required