Data Security in Business Analytics: How Your Accounting Data Is Protected

The question of security comes up in almost every conversation we have, and rightly so. Accounting data is a company’s most sensitive information: turnover, customers, salaries, margins.

Below is how security is ensured in practice.

Connecting to the database

The analytics system connects to your accounting data on a read-only basis. This means the reports can see the data but cannot change or delete it: nothing changes in your accounting system.

Data is transmitted over an encrypted connection. If company policy requires it, the connection can be set up over a VPN, in which case the data traffic never touches the public internet at all.

Who can see the reports

Each user signs in personally using multi-factor authentication (MFA), so a password alone is not enough. This means that even a stolen password does not give anyone access.

Access rights are set separately for each employee. In practice, this allows:

  • a branch manager to see only the data for their own site;
  • a sales manager to see only their own customers;
  • the managing director and the finance team to see the full picture.

When an employee leaves, their access is revoked in a single step, unlike Excel files, which linger in mailboxes and on computers.

Where the data is stored

The reports run in the Microsoft Power BI environment, on the same infrastructure used by most of the world’s companies. Microsoft encrypts data both in transit and at rest.

It is worth noting that the analytics system does not usually hold all of your accounting data, only what the reports need.

Why this is often safer than current practice

The usual way of producing reports is to export data to Excel and send it by email. The result: sensitive information sits in dozens of mailboxes and on personal computers, with no control over who has read it or forwarded it on.

A centralised analytics system removes this problem: the data stays in one place, access is controlled, and files no longer travel around.

Access rights in practice

The theory is simple, but implementation often stalls on a single question: who should see what? It is worth settling this before the rollout, not after.

In practice, a simple principle works: rights according to responsibility, not job title:

  • Managing director and finance team: all data.
  • Branch manager: their own site’s figures, including margin, but often without comparison with other branches.
  • Sales manager: their own customers and their own results.
  • Owner or board: summary indicators without operational detail.

The most common mistake is to give everyone everything “to keep things simple”. That works while the company has five people, and becomes a problem when salary or customer margin data reaches people who have no need for it.

What to put in order on your side

The security of the analytics system does not help if the weak link is elsewhere. Three things depend on the company itself:

  • Personal accounts, not shared ones. A shared “management” login means it is unclear who saw what.
  • Revoking access when people leave. This should be part of the leaving process, not something someone has to remember separately.
  • Periodic review. Once a year, it is worth checking whether access rights still match people’s roles.

What this means under GDPR

If the reports contain personal data (about employees, and sometimes about customers who are private individuals), the GDPR applies.

In practice, three things matter: there should be only as much data as the report needs (not “the whole database, just in case”), access should be restricted on a need-to-know basis, and it must be clear who is the data controller and who is the data processor. This is set out in the contract before work begins.

Most financial reports need no personal data at all; summary figures are enough.

Frequently asked questions

Can we use our own Microsoft environment? Yes. If the company already has Microsoft 365, the reports can run there.

Do we need to expose the database to the internet? No. There are several ways to connect, including options where the database remains closed.

Can we restrict what data you can see? Yes. Access is defined in the contract and technically limited to the data needed for the reports.

Have questions about your situation?

Security requirements differ from company to company. Describe your situation and we will tell you what the connection would look like in your case. You can read more about how the rollout works on our Power BI implementation page.

Further reading

Want reports like these for your own business?

Analitika360 builds Power BI reports from the data already in your accounting system — Rivilė, Finvalda or R-Keeper. They refresh automatically, from €59 a month.

Pricing and plans
Analitika360 client stories

Data that helps you decide

See how companies like yours put Analitika360 reports to work in Power BI.

“
We took the standard R-Keeper report package and they tailored it to us on top of that. It all just works.
TB
Tomas B.restaurant owner
“
Twenty ready-made reports — we didn't have to work out what to ask for. Our Finvalda data is finally something you can look at. Recommended.
IM
Ingrida M.accountant
“
What we liked was that Analitika360 already had a 20-report package for Rivilė users — we didn't have to work out our requirements from scratch. We were up and running quickly, and later they adapted several reports to the specifics of our production. It saved us both time and money.
MK
Marius K.finance director
“
We are a group of companies running Rivilė, and consolidated reporting was always a headache. Analitika360 started from the standard 20-report package and then fitted it to our group structure — we now see everything in one Power BI model, and it refreshes itself.
GJ
Giedrė Jankauskaitėfinancial accountant
“
We run six restaurants on R-Keeper and had long been looking for a way to compare results across sites. The standard 20-report package covered most of what we needed, and reports specific to our group were added later.
AŠ
Andrius Š.director of a restaurant group
“
We came to them on a recommendation, and the ready-made 20-report standard for Finvalda users was a pleasant surprise straight away. Management now gets a clear financial picture every Monday, and I no longer spend days exporting data into Excel.
RP
Rasa Petrauskienėhead of accounting
“
We use Rivilė, but we never had time to build reports from scratch. The 20-report package was exactly what we needed — we had it running within a week.
VP
Vaidas P.retail chain manager
“
We have four cafés on R-Keeper and for a long time we ran them on gut feel. The Analitika360 reports showed us things we had simply never noticed. We now decide on the numbers rather than on guesswork.
LK
Laura Kazlauskienėfinance director of a café group