Book a Call
Security & Confidentiality

Your data stays in your tools, under your accounts.

The simplest way to keep financial data secure with an outsourced team is to never hand it over. We work inside the software you already own, as named users you can remove at any time. Every line on this page is current practice, not aspiration.

Two access modes. Your choice.

Both modes share one principle: the data lives where you control it, not where we do.

Mode 1: Inside your systems

We work as named users in your QuickBooks Online, Xero, Gusto, Bill.com, Ramp, or Stripe, with role-based permissions and your admin rights untouched. Your data never leaves your environment.

Mode 2: Firm-hosted for CPA practices

For firms, our seats work inside your practice management, DMS, and client accounting stack, under your letterhead and your controls. Work runs on hardened virtual desktops with encrypted storage, and client data stays in the firm's environment at all times.

The safeguards behind it

Plain controls, applied without exception.

Two-factor authentication

Required on the accounting and practice systems we access. Individual named logins only. No shared credentials.

NDA by default

Signed before onboarding, covering your business and your data. Yours or ours, whichever your counsel prefers.

Documented access revocation

Offboarding includes a written access-removal step. And since it is all your accounts, you hold the kill switch at all times.

Separated duties

We prepare; you approve. We never hold authority to move money, sign returns, or act on your behalf with third parties.

Hardened virtual workspaces

Client work happens on secured virtual machines with screen-lock and download restrictions. Nothing lives on personal laptops.

Encrypted storage and transfer

Working files sit on encrypted drives and move through access-controlled shared folders, never loose email attachments.

AI with guardrails

AI assists categorization, anomaly flags, and first-pass checks inside controlled systems. Client data never goes into public AI tools.

Least-privilege access

Access is scoped to the engagement: the systems the work needs, nothing more, reviewed as the engagement changes.

Clear engagement boundaries

  • We do not prepare tax returns or provide legal advice. Your CPA or attorney keeps that role; we keep your side of the numbers clean.
  • We never hold authority to move money. Payments are prepared for your approval, in your systems.
  • We never value a business whose books we keep. Our valuation independence policy keeps the two lines cleanly separated.

Tools we commonly work in: QuickBooks Online, Xero, Gusto, Bill.com, Melio, Ramp, Mercury, Stripe, Shopify, Keeper, and standard cloud document storage.

Questions

Security questions, answered plainly

In your tools, under your accounts: your QuickBooks Online or Xero file, your bill-pay and payroll platforms, your cloud document storage. We work inside your environment as named users. We do not move your data onto our servers or proprietary software, and you keep full admin ownership of everything.
Yes, as standard, before any access is granted. We can work from your template or ours. For CPA firms, the engagement also includes non-solicitation terms covering your clients and staff.
Only the named people assigned to your engagement, each with their own login and role-based permissions. Two-factor authentication is required on the systems we access. No shared logins, ever.
Access revocation is a documented step of offboarding. Because everything runs in your accounts, you can also remove our users yourself at any time. You never have to ask us for your own data, and your books, files, and history stay exactly where they always were.
No. Wherever the bank supports it, we work with view-only or read-only access for statement feeds and reconciliations. Money movement stays entirely with you. We never hold authority to move funds.
Yes, deliberately and with guardrails. AI speeds up transaction categorization, anomaly detection, and first-pass reconciliation checks, which is a large part of how we keep turnaround fast. It runs inside controlled systems, your data never goes into public AI tools, and a senior accountant reviews every close before anything reaches you.
No, on both counts. We do not prepare tax returns, give legal advice, or hold authority over your funds. Those boundaries are deliberate: they keep duties separated and your controls intact.

Want our security practices in writing?

We will walk through them on a call and put them in the engagement letter. Ask anything, including the hard questions.

Book a Call