Tool Safety Index

A great tool and a safe tool are two different questions.

The market can tell you which accounting software is best. It cannot tell you what a vendor's binding terms let them do with your client data. So we read the actual terms of service, privacy policy, and DPA for every tool here, and summarize where each vendor's terms land for client data. Supported — the terms support it on the normal business tier. Conditional — supported once you get one specific setting or tier right. Not supported — a binding clause means the terms don't support client data. Undisclosed — the public terms don't say yet. It's our read of the published terms, not a recommendation about the product — every entry is dated and cited to primary source. Behind each one sits a scorecard of five independent checks — no-training, DPA, certifications, US residency, retention — with no composite score: each check stands alone so you can challenge any single cell. A separate connectivity note tracks which tools expose an API or MCP. Open any tool to see its alternatives in the same category, or add two to four tools to the compare tray for a side-by-side scorecard.

Help us keep this right. Every status here is a best-effort read of each vendor's terms as of the date on the card — with 228 tools, we don't guarantee we caught everything, and vendors change terms without notice. If you use a tool and something looks wrong or outdated, open it and hit Flag for review with what you saw. Every flag is tracked and re-verified against primary source, and the entry is corrected or the flag answered. That loop is the point.
228tools tracked
228posture verified
41supported on the business tier
17terms don't support client data
147confirmed API or MCP

How to read the cards

The five checks

No-trainingDPACertificationsUS residencyRetention & deletion

Status

meets the barpartial — read the notefailsrecord too thin

Card icons are tinted by status — hover for the note, click the card for the detail and cited clause. BAA (HIPAA) sits in the detail view; it matters only for firms serving healthcare clients.

228 tools

Click any tool for its full posture, sources, and the exact clause.

Each status comes from reading the vendor's own binding documents, terms of service, privacy policy, data processing addendum, trust center, and sub-processor list, not the marketing. When a security page and a contract clause disagree, the contract wins. These are use-based summaries of what each vendor's published terms support for putting client data in — our read of those terms, not a recommendation about the product.

The scorecard breaks each status into five independent checks (no-training, DPA, certifications, US residency, retention), with a BAA (HIPAA) note in the detail view for firms whose clients include healthcare providers. Nothing is averaged into a number — ✓ meets the bar, ◐ is partial and a flag to read the note, ✗ fails, and ? means the public record is too thin to say. Connectivity (API / MCP) is listed separately because it is a capability, not a safety rating: a connector is only as safe as how you configure it, and a powerful connector on a weak-posture tool is still a weak-posture tool.

Educational, not legal advice. Each status reflects the vendor's published terms as of the date shown and can change. An enterprise agreement or signed DPA may override a vendor's public terms. Confirm the current terms before you rely on any status, and make your own call. If you are a vendor and your terms have changed, tell us and we will re-vet.