Mattsson 577552ca94 docs(privacy): name Anthropic in the Bedrock row, state replay deny-by-default, pin disclosures to code (#1766)
* docs(privacy): name Anthropic in the Bedrock row, state replay deny-by-default

A prospect compared our security claims with a stale published DPA that
listed Anthropic and OpenAI as US processors and read the privacy page's
bare AWS row next to 'delas inte med Anthropic' as a contradiction
(#1674). The in-repo pages were factually right but nothing pinned them
to the code, and the Bedrock row never said whose models run inside it.

- Sub-processor table: the AWS row now states the models are Anthropics
  Claude, run entirely inside Amazon Bedrock (eu-north-1, Stockholm),
  and that Anthropic is the model vendor, not a sub-processor, and
  receives no data. Matches lib/ai/provider.ts: hosted inference is
  AnthropicBedrock, default region eu-north-1; no OpenAI code path
  exists anywhere.
- PostHog row: the session-replay paragraph now states the
  deny-by-default guarantee: masking is the default and cannot be
  turned off, every input is masked with no exceptions, untagged new
  UI over-masks rather than leaks. Matches instrumentation-client.ts
  (maskAllInputs: true, maskTextSelector '*', no maskInputFn) and
  lib/analytics/replay-masking.ts.
- New source-content test locks the disclosures to the code so they
  cannot drift apart silently: no OpenAI dependency or mention, region
  claim equals the provider default, Anthropic named inside the Bedrock
  row, DPA keeps /privacy as the single sub-processor list, replay
  config still deny-by-default.

The artifact the prospect actually read (published DPA PDF or marketing
security page) lives outside this repo and needs founder/legal action.

Refs #1674

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Signed-off-by: Emil <emilmattsson14@gmail.com>

* fix(privacy): drop unverifiable underbitraede claim, state only code-provable facts

Adversarial review of the #1674 branch found two overstatements:

1. The Bedrock row asserted 'Anthropic, som ar modelleverantor men inte
   underbitraede'. Whether Anthropic is a sub-processor of AWS is a
   contractual matter between AWS and Anthropic and cannot be verified
   from this repo, and the issue explicitly forbade invented legal
   wording. The row now states only what the code shows: AI requests go
   to Amazon Bedrock and the models used are Anthropics Claude models
   running inside Bedrock. No claim about Anthropics sub-processor
   status in either direction. The pre-existing footnote below the
   table is untouched (identical to main).

2. The DECISIONS.md entry claimed 'no code path sends data to
   Anthropic'. False as a global claim: lib/ai/provider.ts
   createAiClient() builds a direct Anthropic API client when
   AI_PROVIDER=anthropic or when ANTHROPIC_API_KEY is set without
   static AWS keys (the documented self-hosted path), and the region is
   process.env.AWS_REGION || 'eu-north-1', a default rather than a
   guarantee. The entry now says the hosted posture is Bedrock by
   credential precedence, acknowledges the direct API path, and routes
   the underbitraede question plus published DPA PDF / marketing page
   alignment to founder/legal.

The source-content test now pins the corrected row wording, asserts
the row contains no underbitraede verdict, and no longer cements the
removed sentence.

Refs #1674

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Signed-off-by: Emil <emilmattsson14@gmail.com>

* test(privacy): track the openai-compatible BYO provider added on main

Signed-off-by: Emil <emilmattsson14@gmail.com>

---------

Signed-off-by: Emil <emilmattsson14@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-20 21:36:47 +02:00
2026-07-21 23:00:15 +02:00
2026-06-12 16:35:30 +02:00
2026-07-21 23:00:15 +02:00
2026-07-24 15:03:50 +02:00
2026-07-21 23:00:15 +02:00
2026-07-05 03:05:09 +02:00
2026-07-24 15:03:50 +02:00
2026-07-23 16:16:55 +02:00
2026-07-05 03:05:09 +02:00
2026-07-05 03:05:09 +02:00

Accounted

Open-source Swedish accounting software for sole traders (enskild firma) and limited companies (aktiebolag). Double-entry bookkeeping that complies with Swedish accounting law, built to be operated by you or by your AI agent.

License: AGPL-3.0-or-later Core Build pg-real tests Docker

Website · Hosted app · Documentation

Why Accounted?

Compliant by construction. Accounted implements double-entry bookkeeping under Swedish accounting law (Bokföringslagen). Voucher immutability, sequential voucher numbering, period locks, and 7-year document retention are enforced by database triggers, not by convention. Corrections are made the legal way, with reversal entries (storno), never by editing history. See ARCHITECTURE.md for how.

Agent-native. The full bookkeeping engine is exposed as 100+ MCP (Model Context Protocol) tools with scoped API keys, so an AI agent can do the books in Accounted: categorize transactions, draft vouchers, reconcile periods, and prepare declarations. Posting is staged for human approval, so the agent proposes and you decide.

Yours to run. AGPL-3.0 licensed and fully self-hostable with Docker and Supabase. Use the hosted version at app.gnubok.se or run your own.

Features

  • Double-entry bookkeeping -- BAS 2026 chart of accounts, draft/commit workflow, sequential voucher numbering
  • Invoicing -- Create, send, and track invoices with mixed VAT rates and PDF generation
  • Bank reconciliation -- PSD2 bank connection via Enable Banking, 4-pass automatic matching
  • VAT declaration -- SKV 4700 form mapping, per-rate breakdown, EU/export handling
  • Tax reports -- NE-bilaga, INK2, SRU export for Skatteverket
  • Payroll -- Salary runs, payslips, and AGI (arbetsgivardeklaration) employer declarations
  • Supplier invoices -- Registration, payment tracking, input VAT deduction
  • Document archive -- SHA-256 integrity, 7-year retention enforcement, full archive ZIP export
  • SIE import/export -- Standard Swedish accounting interchange format
  • Agent access (MCP) -- 100+ bookkeeping tools over the Model Context Protocol, with scoped API keys and staged approvals
  • Extension system -- Opt-in plugins for AI categorization, receipt OCR, email, calendar, and more

Self-Hosting

git clone https://github.com/erp-mafia/accounted.git
cd accounted
./setup.sh              # Prompts for Supabase credentials, generates .env
docker compose up -d

You need a Supabase project and must apply the database migrations before first use. See docs/SELF-HOSTING.md for the full step-by-step guide, including Supabase setup, auth configuration, optional features (AI, email, push notifications), and troubleshooting.

Development Setup

Prerequisites: Node.js 20+, a Supabase project.

npm install
npm run dev       # Start dev server (auto-generates extension registry)
npm test          # Run tests
npm run build     # Production build
npm run lint      # ESLint

See CONTRIBUTING.md for the full development workflow.

Tech Stack

  • Framework: Next.js 16 (App Router), React 19, TypeScript (strict)
  • Database: Supabase (PostgreSQL + Row Level Security + email/password auth + TOTP MFA)
  • Styling: Tailwind CSS 4 + shadcn/ui
  • Integrations: Enable Banking (PSD2), Anthropic SDK, LangChain, OpenAI, Resend, JSZip

Documentation

Community

Contributing

Contributions are welcome. See CONTRIBUTING.md for the full guide.

All commits require a DCO sign-off (git commit -s).

License

AGPL-3.0-or-later with an extension exception: third-party extensions that interact solely through the documented Extension API may be licensed under any terms, including proprietary. See LICENSE for details and NOTICE for third-party attributions.

S
Description
Accounted — svensk bokföringsmotor (AGPL, BAS 2026, BFL-compliant, 150+ MCP tools). Finance-kapacitet brevet ERPNext. ADR-ENGAGEMENT-001-tillägg.
Readme AGPL-3.0 56 MiB
Languages
TypeScript 93%
PLpgSQL 5.8%
JavaScript 0.4%
HTML 0.3%
MDX 0.2%
Other 0.1%