Taokeh

Trust & security

Your books are yours. Here's how we keep it that way.

Taokeh holds a Malaysian SME's books — its sales, its cash, who owes what, the numbers you file to LHDN. For a tool like that, security and honest data ownership aren't a feature you add later; they're the product. This page sets out plainly how your data is protected, how the AI features stay on a leash, and how you take everything out whenever you choose to leave.

Your workspace is isolated

Separated at the database level

Every workspace is kept apart in the database itself — Postgres row-level security is enforced on every table, and every query runs scoped to your workspace. Isolation doesn't rely on the application code remembering to filter; it's enforced one layer down, where the data lives.

Two-factor sign-in and passkeys

Every seat can use two-factor sign-in with an authenticator app, or a passkey. A workspace-wide require-2FA policy lets you insist on it for everyone.

Role-based seats

Give each person only what they need. A viewer can look at the books but never post; posting rights are granted, not assumed.

Your books are tamper-evident

A hash-chained audit trail

Every posting lands on a hash-chained audit trail, so a later edit can't be quietly slipped in — a change to the history shows up.

Void and repost, not silent edits

Documents are corrected by void-and-repost, which preserves the original numbering. You get a clean, honest record of what changed — not an overwrite that pretends it was always this way.

Backed up — and we rehearse the restore

Encrypted backups (AES-256)

Backups are encrypted with AES-256. Your books are backed up daily, with a fuller copy — attachments included — every week, and automatically on every schema change, so a structural update never leaves you without a fresh copy.

A monthly restore drill

Once a month, an automated drill restores the latest backup into a clean environment and verifies every journal entry still balances to the cent before we call it good. A backup you've never restored is a guess; this one is checked.

An untested backup is a hope, not a backup — ours is rehearsed monthly.

How you take your data out

Export any time, no gatekeeping

Pull your books out whenever you like — reports and CSV exports, on your terms. We don't hold your data behind a "contact sales" wall to get it back.

Stop paying, stay readable

If you stop paying, your workspace goes read-only — it isn't deleted. Every invoice, report and record stays readable and exportable for as long as you need it. Never deleted, never held hostage.

Full deletion on request

Want it all gone instead? Ask, and we'll delete it — write to dpo@taokeh.my.

The AI never posts to your books

Drafts only — a human approves

The AI features — document scan, and the Ask Taokeh connector for Claude, ChatGPT and more — prepare drafts. A human reviews and approves every line before anything touches the ledger. The AI never posts.

You grant access, you revoke it

Connector access is granted by you on a consent screen — read-only, or read + drafts — and it's revocable at any time. No assistant connects on its own.

Your documents aren't training data

Documents you scan are processed to extract the figures on them. They are not used to train AI models.

Where your data lives

Hosted in Singapore

Taokeh runs on managed cloud infrastructure in Singapore — both the application and the database sit in the ap-southeast-1 region.

Authenticated email

Email sent from taokeh.my is authenticated with SPF, DKIM and DMARC, so messages that claim to be from us can be checked as genuine.

Your data, in writing

The details are in our Privacy Policy, PDPA Notice and Data Processing Agreement. For any question about your data — access, correction or deletion — write to dpo@taokeh.my.

Books you can trust, on infrastructure you can check

Everything on this page is how Taokeh works today — not a promise for later.