Third Party Integration Security Requirements
1. Overview
Developers who connect an application to the AccountKit API must keep AccountKit customer data secure. This page sets out what we require and how we assess it.
2. The standard we use
AccountKit has adopted the Security Standard for Add-on Marketplaces (SSAM), published by DSPANZ and the Australian Taxation Office, as the security standard for third party integrations.
Link: https://www.dspanz.org/best-practice/addon-security-standard/
SSAM sets requirements across encryption key management, encryption in transit and at rest, authentication, indirect access to data, server configuration, vulnerability management, audit logging, data hosting, and security monitoring and breach reporting.
We use SSAM because it is the same standard used across the Australian accounting ecosystem. If your application already meets the security requirements of Xero, MYOB or Intuit, you will likely meet ours.
3. Who this applies to
Every integration that connects to the AccountKit API, without exception.
The AccountKit API can return the client list of a registered BAS or tax agent. Under SSAM, that access carries obligations no matter how few connections an integration has, so we do not apply a connection threshold. The depth of assessment varies by the access you request, but every integration is assessed.
4. Access tiers
The access you request sets the evidence we need.
Tier |
Access |
Evidence |
|
1 Restricted |
One way read of client and group names. Write to a single named tool. Reads only its own records. |
Completed SSAM self assessment, or a completed SSAM based security review by another DSP passed within the last 24 months. |
|
2 Limited |
Two way sync of client and group names. Write to multiple tools. Read, change or delete its own records. |
Tier 1, plus a documented review of authentication and API token handling. |
|
3 Extended |
Read and write across all client data excluding personal information, plus document management and other integrations. |
Tier 2, plus ISO 27001 or SOC 2 Type II covering the connecting product, a penetration test summary from the last 12 months, and a risk assessment. |
|
4 Full |
Read and write across personal information and all client data, document management and other applications. |
Tier 3, with certification mandatory, a full penetration test report, and an audit right. |
A listing in another provider’s app store is not evidence. We need the completed review itself. Where you rely on a certificate, we will read the scope statement to confirm it covers the product connecting to AccountKit.
5. Breach reporting
Tell us immediately, and in any event within 24 hours of becoming aware, if you have a security incident affecting AccountKit customer data or your AccountKit credentials.
Email security@account-kit.com with what happened, when you found it, what data was or may have been affected, and what you are doing about it. Send updates as you learn more.
You are responsible for investigating the incident and for notifying your users and any regulator that needs to know. AccountKit reports incidents involving a third party integration to the Australian Taxation Office.
6. Annual review
Every integration is reviewed once a year. We ask you to confirm in writing that you still meet the standard for your tier, provide current evidence, and confirm the scopes you hold still match what your integration does.
7. If you fall short
If your integration no longer meets the standard, we will write to you describing the problem. You then have 30 days to give us a treatment plan and 90 days from our notice to complete the work. If it is not resolved by then we may limit or withdraw your access and remove any listing.
Where customer data is at risk we may suspend access immediately.
8. Getting started
There are two ways in. Both cover the same ground and lead to the same assessment.
8.1 Through a developer account
Sign up at [link to come]. The process takes you through the following steps.
1. Accept the Third Party Integration Security Terms.
2. Tell us about your integration: what it does, who it is for, and the purpose of each scope you need.
3. Choose your scopes. The scopes you select set your access tier automatically, and the tier tells you what evidence we need. You will see this before you go any further, so there are no surprises later.
4. Provide your evidence. What we need depends on your tier, as set out in section 4.
5. We review what you have given us and come back to you.
8.2 By agreement
Where you would rather sign a document than accept terms online, or where your organisation requires it, email developers@account-kit.com with a description of your integration, the scopes you need and the purpose of each.
We will assign your tier, tell you what evidence we need, and send you the Third Party Integration Security Agreement to sign. It carries the same obligations as the online terms.
8.3 What happens next
Whichever route you take, we issue production credentials once your assessment is complete and approved. Until then you can build against our sandbox, which uses test data only.
Where something is missing, or a certificate does not cover the connecting product, we will tell you what we need rather than simply declining.
If you later need wider access, request a new tier assessment. Do not assume wider scopes will be granted on the strength of your original assessment. We will not widen your access until the new assessment is complete.
If anything about this process does not fit what you are building, email developers@account-kit.com and we will work it out with you.

