Data Handling And Security

Finance tools require trust. This page explains what the beta plugin accesses, what it writes to your workspace, and what to avoid sharing — with full detail on the airCFO-operated QuickBooks connector.

This is a plain-English beta guide. It is not legal advice and not a substitute for a published privacy policy or terms of service — both are required before any public, non-gated launch. Confirm your company’s internal data policies before connecting production systems.

What The Plugin Connects To

The plugin can connect Claude to:

Authentication is handled through per-user OAuth in your browser as workflows invoke each connector.

Read-Only Product Intent

The plugin is designed for read-only finance analysis.

Workflow skills should not write to QuickBooks, Stripe, Ramp, or Mercury. They are intended to read data, summarize it, map it into your finance profile, and produce analysis for human review.

If Claude ever proposes a writeback action, stop and review before proceeding.

What Gets Written To Your Workspace

The plugin creates a ContextOS folder in a location you approve, usually:

~/Desktop/ContextOS/

That folder may include:

The builder also saves a small pointer so future workflows can find this folder without loading your whole profile every session, and — only with your OK — may add a short note to your workspace configuration. It never writes the full profile into your configuration.

These files may contain sensitive business context: account names, vendor names, reporting definitions, and financial judgment calls. Store the folder according to your company’s data policies.

What Not To Store

Do not place the following in finance-profile.md, account-map.csv, or shared context docs:

Use names, last-four identifiers, and internal IDs only where needed.

Connector Note For Beta

Stripe, Ramp, and Mercury use their own configured remote MCP endpoints — you authorize each directly with that vendor.

QuickBooks uses an airCFO-operated MCP server during beta. Because that server is run by airCFO (not Intuit), the section below documents exactly what it does and does not do with your data.

If you are not ready to authorize production finance data, use a sandbox or test company file while evaluating the plugin.

The QuickBooks Connector (Beta): Security And Privacy

The QuickBooks connector is a multi-user, remote MCP server, currently in gated beta. You connect your own QuickBooks Online company through Intuit’s OAuth, which gives Claude read-only access to that company’s accounting data (P&L, balance sheet, cash flow, general ledger, AR/AP aging, vendor spend, and individual transactions).

Verified against the connector’s source code and deployment on 2026-06-25.

The core guarantees

Hosting and who touches your data

Encryption

Logging

Good to know

Security or privacy questions: email alex@aircfo.com with “Security” in the subject line.

What If A Connector Is Missing?

The plugin can continue with partial setup. Missing systems should become placeholders and open questions in the finance profile.

Example:

[PLACEHOLDER: Ramp is not connected, so recurring vendor rules still need to be mapped.]

That is preferable to Claude guessing.

Human Review Required

Outputs should be reviewed before they are used in:

The plugin helps gather and interpret context. It does not replace finance judgment.