Is it safe to connect Exact Online to AI?

Yes, provided the integration settles three things: who gets access, what that access may do, and what is retained. Ledger Botje connects Exact Online to AI assistants through the Model Context Protocol using OAuth 2.1 and PKCE, runs on servers inside the EU, is read-only by default, and ships a data processing agreement under article 28 GDPR with every plan.

How does Ledger Botje get access to my administration?

Through OAuth 2.1 with PKCE, the authorisation standard Exact Online itself uses. You sign in at Exact Online and grant permission there; Ledger Botje receives a token and never sees your password. That token is bound to your account and your administrations, and you can revoke it at any moment inside Exact Online.

  • No passwords: the integration works purely with tokens issued by Exact Online.
  • PKCE protects the authorisation flow against interception of the authorization code.
  • Revoking needs no involvement from us; you do it straight from Exact Online.
  • All traffic runs over HTTPS/TLS, including between the AI assistant and the MCP server.

Can the AI change things in my accounting on its own?

Not by default. A Basic plan is entirely read-only: the MCP server then returns read tools only, and write actions simply do not exist in the toolbox the AI sees. Write access is a deliberate choice the administration owner switches on.

Of the 292 available MCP tools, 122 are read-only and 170 write. With write access off, those 170 write tools never appear in tools/list, so the AI cannot call them, not even by accident.

  • Basic: read-only. Advanced: read and write, enabled per administration.
  • Disabled write tools are not offered to the AI assistant at all.
  • Every tool call is logged with timestamp, user and stated reason.

Where is my data stored and what is retained?

Ledger Botje keeps an encrypted cache of your Exact Online data so it can answer quickly without hitting the Exact Online API on every question. That cache sits on servers inside the EU and synchronises automatically. Revoke the connection and the stored data is deleted.

  • Hosting inside the EU (the Netherlands and France), at Scaleway.
  • Payments run through Mollie; we store no payment details ourselves.
  • Logs of tool calls are kept for 180 days and then deleted automatically.
  • No Dutch citizen service numbers (BSN) are processed.

Is my company data used to train AI models?

Not by us. Ledger Botje uses your Exact Online data solely to answer your questions and carry out the actions you ask for. What your AI assistant does with the conversation is governed by that provider's settings and terms - a separate choice that sits outside Ledger Botje.

That distinction matters: the integration supplies the data, the AI assistant decides the presentation. If you need certainty that conversations are not used for training, check the policy of ChatGPT, Claude, Copilot or whichever assistant you use.

What if someone hides malicious instructions in my data?

That is prompt injection: text in, say, an invoice description or a customer name written to give the AI assistant instructions. It is a real risk the moment an AI both reads your data and can act on it, and it deserves an honest answer: no integration can rule it out entirely.

What Ledger Botje does structurally is limit the blast radius. The AI can only call tools the MCP server offers, only within the administrations you authorised, and only if write access is deliberately on. Every call is logged, so afterwards it is traceable what happened.

  • Read-only by default means injected instructions cannot change anything.
  • The AI cannot make arbitrary API calls, only the tools the server offers.
  • Full audit trail of tool calls, retained for 180 days.
  • Recommended: have a human confirm write actions with financial impact.

Do I get a data processing agreement?

Yes. Every plan includes a data processing agreement under article 28 GDPR, which you generate online yourself and download as a PDF. It covers the processing purposes, the sub-processors, the retention periods and the arrangements around data breaches.

A data protection impact assessment (DPIA) has also been carried out on the processing. The retention periods on this page follow directly from the measures that came out of it.

Four ways to connect Exact Online to AI

The choice determines who manages access, where your data lives and what you can trace afterwards.

Ledger Botje (MCP) Exact Online AI Assistant Your own API integration iPaaS (Zapier, Make)
Authorisation OAuth 2.1 + PKCE via Exact Online Built into Exact Online Build and maintain it yourself Varies per platform and connector
Where data lives Encrypted cache inside the EU At Exact Online Wherever you host it Depends on the provider
Write access Off by default, enabled per administration Determined by Exact Online Bounded by you Configured per scenario
Audit trail Every tool call logged, 180 days Within Exact Online Build it yourself Run history per scenario
Revoking Directly in Exact Online, data is deleted Within Exact Online Arrange it yourself Disconnect the connector
Data processing agreement Included, self-service Through Exact Online Not applicable Request per provider
Works with 9 AI assistants via MCP The Exact Online assistant Whatever you build Whatever the platform supports

tpl_faq_heading

Does Ledger Botje see my Exact Online password?

No. The integration runs on OAuth 2.1: you sign in at Exact Online itself and grant permission there. Ledger Botje only receives a token and never sees your credentials.

Can I revoke the connection?

Yes, at any time and without involving us: revoke the authorisation inside your Exact Online environment. The data stored at Ledger Botje for that administration is then deleted.

Is my data stored outside the EU?

No. The encrypted cache of your Exact Online data sits at Scaleway in the Netherlands and France. Payments run through Mollie. Both are listed as sub-processors in the data processing agreement.

How long are my AI conversations retained?

Log records of tool calls are retained for 180 days and then removed automatically by a daily cleanup job. That period follows from the DPIA and is set out in the data processing agreement.

Could the AI delete something by accident?

Not while write access is off, because the write tools then do not exist in the toolbox the AI sees. With write access on, the AI can perform the same actions you would perform yourself in Exact Online. So have a human confirm actions with financial impact.

Is Ledger Botje ISO 27001 certified?

Ledger Botje itself is not ISO 27001 certified. The underlying infrastructure runs at a hosting provider that holds ISO 27001 certification. A DPIA has been carried out on the processing and a data processing agreement under article 28 GDPR is available.

Key facts

  • 292 MCP tools for Exact Online: 122 read-only and 170 write.
  • Works with 9 AI assistants: ChatGPT, Microsoft Copilot, Claude, Gemini, Mistral, Perplexity, Grok, Cursor and OpenClaw.
  • Connects via the Model Context Protocol (MCP) over Streamable HTTP, using OAuth 2.1 and PKCE.
  • From €39 per month. Every plan starts with a free 14-day trial, no credit card.

Tool counts verified on 25 July 2026.

Last updated: 25 July 2026