Is it safe to let an AI into the books? Here is exactly what happens.
The connector is a small server that sits between your AI app and Fortnox. You sign in with your own Fortnox user and choose which modules the AI may reach. When you ask something, the AI proposes a call, your app asks for your approval before a write is sent, and the connector performs the call in Fortnox with your permissions. The answer passes straight back to you.
Your bookkeeping is stored in Fortnox and nowhere else. Sidcom keeps no copy of it, and no passwords. What we hold is an encrypted sign-in token and three days of technical metadata. Sidcom AB is a Swedish company and acts as your data processor, under a data processing agreement you can sign electronically.
That is the short version. Below is the long one, for anyone who wants to understand exactly how it works. The privacy policy has the formal wording.
// what_actually_happens
From your question to Fortnox and back, in five steps.
- 01
You ask in your AI app
You write in Claude, ChatGPT or Copilot as usual. The conversation itself stays with your AI provider under your agreement with them, exactly as it does without the connector.
- 02
The AI picks a tool, and your app checks with you
The connector exposes a handful of tools and marks each one as reading or writing. Reading, such as listing invoices, runs directly. Before a write, such as creating an invoice, your AI app asks for your approval. In Claude you can also lock every tool to always allow, ask each time, or block.
- 03
The connector calls Fortnox as you
The call goes to Fortnox with your own sign-in token, and only within the modules you ticked when you connected. Fortnox then applies your user's permissions. What you cannot do in Fortnox, the AI cannot do either.
- 04
The answer passes straight through
Fortnox responds, and the data flows through the connector in memory and back to your AI app. It is not written to disk, not stored in a database and not logged in readable form.
- 05
What remains afterwards
In Fortnox, the change is visible as your user, as if you had done it by hand. At Sidcom, one log line with timestamp, tool name, status code and response time, deleted after three days. Nothing else.
// approval
Will the AI do things without asking?
The most common question we get, and the most important one. The answer has several layers, and only the first one is enforced by something you control rather than by software you have to trust.
Reading and writing are separate tools
The connector uses a small set of tools, and each is marked as reading or writing. Your AI app knows the difference before anything runs, which is what lets it ask you at the right moment instead of at every question.
Your AI app asks before a write is sent
Creating, changing, booking, sending and uploading are write tools. Claude and ChatGPT ask for your approval before running one. In Claude you can also set each tool to always allow, ask every time, or block. For a strictly read-only setup we recommend block rather than ask, since an approval in the middle of a long run is easy to click through.
Want read-only? Use a Fortnox user without write rights
The one setting nobody can click past is Fortnox itself. Connect with a Fortnox user that has no write permissions and nothing can be written, whatever happens in the AI layer. If you would rather use your normal user, block the write tools in your AI app instead, a softer lock but a lock.
Creating and booking are separate steps
An invoice the AI creates is neither booked nor sent. Booking it, sending it or approving a supplier invoice for payment are their own actions, and each one goes through your app's approval on its own.
Nothing in the ledger can be deleted
Fortnox's API lets no integration delete vouchers or invoices, and the connector does not even request that permission. Corrections happen the Fortnox way, with credit notes and reversing entries, which you approve like any other write.
// access_control
The AI gets your access. Exactly yours, nothing more.
There is no separate permission model to administer. Everything the connector can reach is decided by things you already control in Fortnox.
Sign in with Fortnox, not with us
You authorise the connector through Fortnox's own sign-in (OAuth). Sidcom never sees your password. What we receive is a token that Fortnox can revoke at any time.
Your Fortnox permissions are the ceiling
Fortnox limits every API call to the connecting user's own permissions, not to what the app asked for. If you cannot approve supplier invoices in Fortnox, neither can the AI. The permissions are administered by a Fortnox administrator under Settings, Administer users.
You choose the modules when you connect
The consent screen lists Fortnox's modules and you tick the ones the AI may reach. An unticked module stays out of reach until you reconnect and add it.
One person, one connection
Colleagues each sign in with their own Fortnox user. Nobody works through someone else's access, and every change in Fortnox is tied to the user it was made through.
Accounting firms: the client decides
A consultant connects with their Digital byrå sign-in and reaches only the client companies where the client has granted them permissions. The same rights as when working in that client's Fortnox directly.
Access ends when you say so
Revoke the connector in Fortnox, disconnect it in your AI app, or, with Fortnox AI Connector, remove the company link or the member. The stored token is deleted, and a deleted token cannot be used again.
// data_handling
What is stored, where, and for how long.
- Your bookkeeping data
- Passes through in memory while a call runs. Never stored, never logged in readable form, never used by Sidcom for training or analytics
- Files you upload
- Streamed to Fortnox through a single-use link that expires after ten minutes. Not stored at Sidcom
- Sign-in tokens
- Encrypted with AES-256-GCM before storage. The marketplace connectors keep them at most 44 days, Fortnox's own refresh cycle. Fortnox AI Connector keeps them in a database created with EU jurisdiction and deletes them when the link or the member is removed
- Operational logs
- Metadata only, timestamp, tool name, status code, response time and company ID. Deleted after three days
- Account data (Fortnox AI Connector)
- Organisation, members, seats and invoices, in a database in Stockholm
- Retry cache
- The response to a create call is kept for up to 60 seconds so a retried request does not create a duplicate
- Hosting
- Cloudflare Workers with TLS on every connection. Processing runs on the node nearest you, normally within the EU, though without a formal region guarantee. The token store is replicated globally under Standard Contractual Clauses and the EU-U.S. Data Privacy Framework
- Your AI provider
- What the AI fetches from Fortnox becomes part of your conversation with Anthropic, OpenAI or Microsoft, under your own agreement with them. They are not Sidcom's sub-processors
// gdpr_and_paperwork
The paperwork your accountant will ask for.
We get these questions before almost every purchase by a firm, or by a company with a data protection officer. So here are the answers up front.
Who is controller, and who is processor?
You are the controller of your bookkeeping data. Sidcom is your processor for the data that passes through while a call runs, and processes it only on your instruction, never for its own purposes. For sign-in tokens and account details Sidcom is an independent controller, since that is our own customer relationship with you. The privacy policy spells out both.
A data processing agreement you can sign today
Sidcom has a standard DPA for the Fortnox connectors: master terms, a service schedule that describes exactly what is processed and where, and the technical and organisational measures. It is signed electronically. Email hello@sidcom.ai and we send it filled in with your company details.
Named sub-processors, no silent additions
Cloudflare hosts the service and stores the tokens. If you buy Fortnox AI Connector directly from Sidcom, Supabase holds the account database in Stockholm and Stripe handles card payments. Fortnox and your AI provider are not sub-processors. Changes are announced 14 days ahead, with a right to object.
If something goes wrong
A personal data breach affecting your data is reported to you without undue delay, with what you need for your own report to IMY within the 72-hour deadline. Security concerns go to hello@sidcom.ai and reach the people who built the connector.
Certifications, honestly
Sidcom holds no ISO 27001 or SOC 2 certificate of its own. We are a small Swedish company and say so. The infrastructure we run on, Cloudflare, is certified under both, and we answer written security questionnaires and share the DPA, the architecture and the retention terms above with anyone evaluating us.
Ending it, completely
Disconnect in your AI app and revoke the connector in Fortnox, and the token is gone. For a marketplace connector, also end the subscription in Fortnox App Market, since revoking access alone does not stop the billing. For Fortnox AI Connector, remove the company links or delete the organisation. Ask, and we confirm the deletion in writing.
Security questions, answered.
Will the AI change my books without asking me?
The connector marks each tool as reading or writing, and your AI app asks for your approval before a write tool runs. Claude also lets you lock each tool to allow, ask or block. And whatever the app does, the AI can never exceed the permissions of the Fortnox user you connected with.
Can I run it read-only?
Yes. The safest way is to connect with a Fortnox user that has no write permissions. Then nothing can be written, whatever the AI or the app does, because Fortnox itself refuses. If you want to use your normal user instead, block the write tools in Claude (create, update, delete, action and the two upload tools) and allow the read tools (get, list, download and describe). Choose block rather than ask, so nothing can be approved by habit. It is a softer lock than Fortnox permissions, but quicker to set up.
Can the AI delete vouchers or invoices?
No. Fortnox's API does not allow any integration to delete vouchers or invoices, and the connector does not request that permission. Invoices are cancelled or credited, vouchers are corrected with a reversing entry, and both are writes your app asks you to approve.
Does Sidcom store my accounting data?
No. The data passes through in memory while a call runs and is not written to disk or to a database. The only exceptions are technical: the response to a create call is cached for up to 60 seconds so a retry cannot create a duplicate, and the logs hold metadata for three days. Your books live in Fortnox.
Does Sidcom see my Fortnox password?
No. You sign in on Fortnox's own page, and Fortnox hands the connector a token. The token is encrypted before it is stored, and you can revoke it at any time in Fortnox.
Where is the data processed? Is it within the EU?
Partly, and we would rather be precise than reassuring. Account data and the company tokens of Fortnox AI Connector are stored in the EU, in Stockholm and in a database created with EU jurisdiction. Processing runs on Cloudflare's network, normally on a node within the EU for Swedish users, without a formal region guarantee. The store holding the marketplace connectors' tokens is replicated globally, covered by Standard Contractual Clauses and the EU-U.S. Data Privacy Framework. Your bookkeeping data is not stored anywhere at Sidcom.
Is my data used to train AI models?
Not by Sidcom, and that is written into the DPA: no training, no profiling and no analytics on your business data. What the AI fetches from Fortnox becomes part of your conversation with your AI provider, and their use of it follows your agreement and settings with them. Business plans from Anthropic, OpenAI and Microsoft do not train on customer data by default, and the consumer plans have a setting for it. Check the plan you use.
What does Anthropic, OpenAI or Microsoft see?
Your conversation, including the Fortnox data the AI fetched to answer you. They are your own provider, under your own agreement, not Sidcom's sub-processor. The connector never sends anything to them on its own. Data moves only as the result of a tool call the AI made in your chat.
Do you sign a data processing agreement, and who are your sub-processors?
Yes. Sidcom has a standard DPA for the Fortnox connectors that is signed electronically. Email hello@sidcom.ai and we send it filled in. The sub-processor for your business data is Cloudflare, which hosts the service. If you buy Fortnox AI Connector directly from Sidcom, Supabase holds the account database in Stockholm and Stripe handles card payments. Fortnox and your AI provider are not sub-processors.
What do you log, and for how long?
Metadata only: timestamp, tool name, status code, response time and company ID. Never the contents of a request or a response. Logs are deleted after three days.
Are you ISO 27001 or SOC 2 certified?
No. Sidcom is a small Swedish company and holds no certificate of its own. Cloudflare, which hosts the service, is certified under both. We answer written security questionnaires and share the DPA, the architecture and the retention terms with anyone evaluating us.
What happens if there is a security incident?
A personal data breach affecting your data is reported to you without undue delay, with the information you need for your own report to IMY within 72 hours. Report suspected issues to hello@sidcom.ai.
We are an accounting firm. What can a consultant reach in a client's Fortnox?
Only what the client has granted them. The consultant connects with their Digital byrå sign-in and picks the client company, and Fortnox applies the permissions that client has given the consultant in their Fortnox. Changes appear in the client's Fortnox under the consultant's name. With Fortnox AI Connector, removing a member revokes all their company links at once.
Can two colleagues share one connection?
No, and you would not want to. Each person signs in with their own Fortnox user and has their own licence or seat. That is what keeps every change in Fortnox traceable to the person who made it.
What if the AI makes a mistake?
It can, like a new colleague can. The guardrails are the ones above: your app asks before a write, created invoices stay unbooked until you approve the booking, nothing in the ledger can be deleted, and every change is visible in Fortnox. For larger jobs, ask the AI for a plan first and approve it before anything runs. Corrections are made the ordinary Fortnox way.
Does the connector affect my other Fortnox integrations?
No. Apps that sync into Fortnox, such as Synka+ or a Shopify connection, keep working as before. The connector reads and writes ordinary Fortnox records and never talks to those services directly.