# Data & Security
How Bev Deck signs people in, keeps each company's data separate, and records changes.
# Sign-in
People sign in with Google, or with an email address and password. Invitations send either a sign-in link or a single-use link to set a password, and sending a new password link cancels the earlier ones. A deactivated user's sign-in is disabled.
What a signed-in user can see and change is set by their role and permissions.
# Your company's data
Your records are stored in Google Cloud (Firebase). Every record belongs to your company's account, and access rules on the server check the signed-in user's company on every read and write. A user of one company cannot read another company's records, whatever the app shows.
Files you attach are stored in Google Cloud Storage, filed under your company's account. See Files.
# Tenant cloud data
Data copied in from connected services, such as your QuickBooks items, accounts, customers and vendors, is stored with your company's records. It is what the app offers you when you link pricing, items and contacts to QuickBooks, and Refresh Data in Settings → Integrations reloads it. See Integrations.
# Document history
Batches and bills of lading keep a history of changes. Choose View History from the record's menu to see who created or changed it, when, and which fields changed.
Inventory is recorded as dated movements rather than overwritten totals, so on-hand quantities can be traced back to the movements that made them. See Inventory.
User and access changes are kept in a separate audit. See Roles & Access.