Third Party Integration Security Agreement
Welcome to the AccountKit developer platform.
These terms set out what we ask of you when you connect an application to AccountKit. Most of it comes down to one thing: our customers are accounting firms, and the data they trust us with belongs to their clients. If you handle it the way we do, you’ll have no trouble here.
We’ve kept this as short as we can, but some of it has to be written carefully. We’re accountable to the tax authorities and regulators in the countries where our customers work, and that accountability extends to the applications connected to us. Where a clause matters more than the rest, we’ve said so.
If anything here is unclear, or you think a requirement doesn’t fit what you’re building, email us at developers@account-kit.com and we’ll talk it through.
Last updated: 28/08/2026. We keep every earlier version here: (none yet). When we change these terms we’ll tell you at least 60 days before the change takes effect.
1. About these terms
1.1 These terms are between AccountKit Pty Ltd ACN 600 935 813 (we, us, our) and the organisation connecting an Integration to the AccountKit Platform (you, your).
1.2 You accept these terms by creating a developer account, requesting API credentials, or using the AccountKit Platform, whichever happens first. If you are accepting on behalf of an organisation, you warrant that you have authority to bind it.
1.3 These terms set the security requirements you must meet to obtain and keep access to the AccountKit Platform, and protect confidential information exchanged between us. They do not oblige us to grant access, and do not create any commercial, licensing or service arrangement. Any such arrangement must be agreed separately in writing.
1.4 We may change these terms. We will publish the new version with a new effective date and tell you at least 60 days before it takes effect. If you keep using the AccountKit Platform after that date, you accept the new version. If you do not accept it, you must stop using the AccountKit Platform and clause 15 applies.
2. Definitions
AccountKit Platform means any product, service or application programming interface made available by us, whether now or in future, including any marketplace through which integrations are listed or distributed.
Confidential Information means information disclosed by one of us to the other that is marked confidential or that a reasonable person would understand to be confidential, including product plans, technical detail, pricing and Customer Data. It does not include information that is public through no fault of the receiving party, was already lawfully known to it, or is independently developed by it.
Customer Data means any data belonging to an AccountKit customer or that customer’s own clients which you access, receive or store through the AccountKit Platform, including client names, group names and any personal information.
Integration means your application, product or service that connects to the AccountKit Platform, whether built by you for general distribution, by another vendor, or by an AccountKit customer for its own use.
Security Incident means unauthorised access to, disclosure of, alteration of or loss of Customer Data, or any compromise of your systems or credentials that could reasonably affect Customer Data.
Standard means the AccountKit Third Party Integration Security Standard, as amended from time to time, published at our Security Requirements Page.
SSAM means the Security Standard for Add-on Marketplaces published by DSPANZ and the Australian Taxation Office, found here.
3. Term
3.1 These terms start when you accept them and continue until ended.
3.2 You may end them at any time by ceasing to use the AccountKit Platform and telling us. We may end them on 30 days notice, or immediately under clause 13.4.
3.3 When these terms end, your access to the AccountKit Platform ends.
4. Compliance with the Standard
4.1 You must meet the requirements of the Standard for the access tier assigned to your Integration, and maintain that compliance for as long as you hold access.
4.2 We assign the access tier. The tier is set by the scopes you request, not by the volume of data you hold.
4.3 We may amend the Standard. Where an amendment imposes a new requirement, we will give you at least 60 days written notice before it takes effect.
5. Scope of access
5.1 You may use the AccountKit Platform only for the scopes we grant you in writing and only for the purpose stated in your application.
5.2 You must not access, collect, store or process Customer Data beyond what is necessary for that purpose.
5.3 You must not sell or licence Customer Data. You must not use Customer Data to train, fine tune, adapt or enhance any artificial intelligence or machine learning model. You must not pass Customer Data to any third party without the consent of the AccountKit customer concerned, and must never pass it for a purpose inconsistent with these terms.
5.4 You must request a new tier assessment before seeking wider scopes. We will not widen your access until that assessment is complete and approved.
5.5 You must publish your own terms of use and privacy policy, make them available to every user of your Integration, and obtain each user’s agreement before use. Those terms must be consistent with these terms and must describe clearly how you collect, store, use and share Customer Data.
5.6 Your Integration is approved for the use case stated in your application. Material changes to its functionality, or to the customers it serves, require our prior written approval.
6. Acceptable use
You must not:
(a) undermine the security or integrity of AccountKit systems, or interfere with other users of the AccountKit Platform;
(b) access any AccountKit system or data without permission;
(c) introduce or upload malicious code;
(d) reverse engineer, decompile or extract source code from the AccountKit Platform;
(e) scrape or bulk download AccountKit websites, data or content by any means, including automated tools;
(f) exceed or attempt to bypass published rate limits;
(g) resell, sublicense or otherwise provide access to the AccountKit Platform;
(h) use the AccountKit Platform for competitive benchmarking, or publish performance information about it, without our written consent;
(i) use the AccountKit Platform in breach of any law, or in breach of export control or sanctions law.
7. Credentials and hosting
7.1 API keys, tokens and secrets we issue to you are Confidential Information. You must store them encrypted, restrict access to staff who need them, and never embed them in client side code or public repositories.
7.2 You must not host any system holding AccountKit credentials or Customer Data on shared hosting infrastructure.
7.3 You must tell us immediately if a credential is or may be compromised, and co-operate with its revocation and replacement.
8. Security Incidents
8.1 You must notify us of any Security Incident immediately, and in any event within 24 hours of becoming aware of it, by email to security@account-kit.com.
8.2 The notice must describe what happened, when it was detected, what Customer Data was or may have been affected, and what you are doing to contain and fix it. You must provide updates as the position becomes clearer.
8.3 You are responsible for investigating the incident and for notifying affected users and any regulator that must be told.
8.4 You acknowledge that we are required to report incidents involving a connected application to the tax authorities and regulators we answer to, including the Australian Taxation Office under the DSP Operational Security Framework, and you consent to us doing so.
8.5 You must not make any public statement identifying us or our customers in connection with a Security Incident without our prior written consent, unless required by law.
9. Notification of change
You must notify us in writing at least 30 days before, or as soon as practicable after where advance notice is not possible:
(a) a change in where Customer Data is hosted, including a change of country;
(b) the addition or replacement of a subcontractor or sub-processor with access to Customer Data;
(c) a material change to your Integration’s function or the data it uses;
(d) the lapse, suspension or narrowing of scope of any certification relied on for your access tier;
(e) a change of control of your organisation.
10. Subcontractors
10.1 You may engage subcontractors to build or support your Integration.
10.2 You remain responsible for their acts and omissions, must bind them to obligations no less strict than these terms, and must notify us under clause 9(b) where they will have access to Customer Data.
11. Annual re-attestation
11.1 Each year, on request, you must confirm in writing that you continue to meet the Standard for your tier and provide current supporting evidence.
11.2 You must maintain a named security contact and keep those details current in your developer account.
12. Monitoring and audit
12.1 We may monitor use of the AccountKit Platform to verify compliance with these terms and to protect the platform, and may ask you at any time for reasonable evidence that your Integration complies.
12.2 For Tier 4 Integrations, we may audit your compliance, or appoint an independent auditor agreed between us, on 30 days notice and no more than once a year unless following a Security Incident.
13. Remediation
13.1 Where we consider you no longer meet the Standard, we will give you written notice describing the failure.
13.2 You must provide a treatment plan within 30 days of that notice, and complete remediation within 90 days of the notice.
13.3 Where remediation is not complete within 90 days, we may limit or withdraw your access, remove any listing of your Integration, and end these terms.
13.4 We may suspend or withdraw your access immediately, without notice and without following clause 13.2, where we reasonably consider Customer Data is at risk, where you breach clause 5 or 6, or where required by law.
14. Confidentiality
14.1 Each of us must keep the other’s Confidential Information confidential, use it only for the purpose of these terms, and disclose it only to personnel and advisers who need it and who are bound by equivalent obligations.
14.2 Each of us must protect the other’s Confidential Information with at least the care we apply to our own, and no less than reasonable care.
14.3 Either of us may disclose Confidential Information where required by law or by a regulator, and must tell the other first where it is lawful to do so.
14.4 When these terms end, each of us must return or destroy the other’s Confidential Information. Clause 15 governs Customer Data.
14.5 This clause continues for 3 years after these terms end, and indefinitely for Customer Data.
15. Ending access and deleting data
15.1 When these terms end or your access is withdrawn, you must stop using the AccountKit Platform and delete all Customer Data you hold, including copies in backups and archives.
15.2 You must confirm deletion in writing within 30 days. Where a law requires you to retain particular data, you must tell us what you are retaining, why, and for how long, and must keep it secure and use it for no other purpose.
16. Branding and publicity
16.1 You must obtain our written agreement before using AccountKit brand materials or referring to AccountKit in promoting your Integration.
16.2 You grant us the right to use your name, logo and Integration materials for the purpose of listing and promoting your Integration.
17. Indemnity
17.1 You indemnify us against all loss, cost (including reasonable legal cost), expense, damage and liability that we incur, whether directly or through a third party claim, arising out of or in connection with:
(a) your breach of these terms;
(b) your use of the AccountKit Platform or Customer Data;
(c) your Integration itself, including any claim by a user of it; or
(d) any claim that your Integration infringes a third party’s rights.
17.2 This indemnity does not apply to loss arising from our own breach of these terms, or from our negligence, wilful misconduct or fraud, or that of our personnel.
17.3 We must take reasonable steps to mitigate any loss to which this indemnity applies.
18. Warranties and disclaimer
18.1 Each of us warrants that we have authority to enter these terms and that doing so does not breach any other obligation we have.
18.2 You warrant that you hold or are authorised to use all intellectual property rights in your Integration, and that it does not infringe the rights of any third party.
18.3 Subject to clause 19.1, the AccountKit Platform is made available on an “as is” basis. We do not warrant that it will be uninterrupted, error free, or fit for any particular purpose, and we do not warrant that your Integration will remain compatible with future versions.
18.4 We may change, update or discontinue features of the AccountKit Platform. We will use reasonable efforts to notify you of changes likely to affect your Integration.
19. Limitation of liability
19.1 Nothing in these terms excludes, restricts or modifies any right or remedy that cannot lawfully be excluded, including under the Australian Consumer Law.
19.2 Neither of us is liable to the other for loss of revenue, profit, goodwill, customers, anticipated savings or reputation, or for any indirect or consequential loss, however arising.
19.3 Subject to clauses 19.1 and 19.4, our total aggregate liability to you under or in connection with these terms is limited to the greater of the total fees you paid us in the 12 months before the claim arose, and AUD $1,000.
19.4 The limits in clauses 19.2 and 19.3 do not apply to your liability under clause 17, or to either party’s breach of clause 5.3, 6 or 14.
20. Notices
20.1 We will send notices to the email address on your developer account. Keep it current.
20.2 You must send notices about security incidents to security@account-kit.com, and about anything else to developers@account-kit.com.
20.3 A notice sent by email is taken to be received on the next business day in Adelaide, unless the sender receives a delivery failure.
21. General
21.1 These terms, in the version in force when you accepted them, together with the Standard, are the whole agreement between us on their subject matter.
21.2 We may amend these terms under clause 1.4 and the Standard under clause 4.3. No other variation applies unless agreed in writing by both of us.
21.3 Nothing in these terms creates a partnership, joint venture, employment or agency relationship.
21.4 You may not assign these terms without our written consent, which we will not unreasonably withhold. We may assign to a related body corporate or in connection with a sale of our business.
21.5 If a provision is unenforceable, it is severed and the rest continues.
21.6 A waiver is effective only if in writing and signed by the waiving party.
21.7 These terms are governed by the laws of South Australia, and each of us submits to the courts of that State.
22. Survival
Clauses 8.4, 8.5, 14, 15, 17, 18.2, 19, 21 and this clause survive the ending of these terms.

