Your clients' data, treated like your own
Lottie was built by accountants, for accountants — so security isn't a bolt-on. From a least-privilege Xero connection to a full audit trail and two-person approval, every part of the product is designed to keep you in control of what happens to your ledger.
Connected with least privilege
Lottie asks Xero for only the permissions she needs to run your month-end — and nothing that lets her touch the rest of your ledger.
Official Xero OAuth
You authorise the connection inside Xero. Lottie never sees or stores your Xero password, and Xero shows you every permission before you approve it.
Reads only what she needs
Invoices and bills, your chart of accounts and trial balance, invoice attachments and the fixed-asset register where used — to build your registers.
Never edits your source data
Lottie only posts manual journals and their reversals. She never edits your invoices, bank transactions or contacts.
Disconnect anytime
Revoke access from Xero or disconnect in-app at any moment — the connection is yours to end whenever you like.
Nothing posts without your rules
Every journal that reaches Xero follows the controls you set — with a complete record of who did what.
Two-person approval
Turn on four-eyes review and no set-up or release journal posts until a second person approves it.
Full audit trail
Every create, amend, post, approval and reversal is logged with before/after detail and exportable activity reports.
You decide when it posts
Journals can post automatically on schedule or be held for review — the choice is set per practice.
Strong account security
Sign-in and team access are protected by modern controls out of the box.
Two-factor authentication
TOTP authenticator-app 2FA is available to everyone and enforced for owner and admin roles; practices can require it for the whole team.
Role-based access
Admins manage the team; read-only reviewers can leave notes but can never edit, post or export financial data.
Hardened sign-in
A 12-character password policy, brute-force lockout and an inactivity auto-lock keep sessions safe.
Your clients stay isolated
Multi-entity work never means mixed-up data.
Per-entity isolation
Each client organisation is kept separate, with its own chart of accounts and nominal-code classification — no cross-client bleed.
Reputable cloud infrastructure
Lottie runs on reputable, professionally managed cloud infrastructure.
Encrypted in transit
All data moving between your browser, Lottie and Xero travels over encrypted HTTPS (TLS).
You own your data
UK GDPR & the ICO
WorkWithLottie is registered with the UK's Information Commissioner's Office (ICO), and a Data Processing Agreement (DPA) is available on request.
Deletion on your terms
You can request full deletion of your data at any time. Data is removed within 30 days of account closure.
We never sell your data
Your practice and client data is used only to provide the service to you — it is never sold or shared for marketing.
Security questions?
Reviewing Lottie for your practice or need our DPA? We're happy to walk through anything.
hello@workwithlottie.com