Security & confidentiality

How we protect what you share with us.

Client financial data is the core of what we handle. Here is what we actually do to keep it controlled, and where we are still building out formal certification.

Access & infrastructure

Data stays inside controlled environments.

Delivery work is done through virtual desktop (VDI) access rather than on individual laptops, so client files and systems are not copied onto local machines. Access is role-based, so team members see only the systems and records their engagement requires.

Virtual desktop access

Work happens inside a controlled virtual environment, not on personal devices.

Role-based permissions

Access to client systems and files is scoped to what each engagement needs.

Encryption

Data in transit and at rest is encrypted as standard practice across engagements.

People & process

Confidentiality is built into how engagements are staffed.

Team members working on client engagements operate under confidentiality obligations, and engagements are scoped up front so access is limited to the people actually doing the work, not the wider team.

Confidentiality commitments

Staff working on client data operate under confidentiality obligations as a condition of the engagement.

Scoped engagements

Each engagement defines who touches which systems and records before work starts.

Data retention

Client data is used only for the engagement it was provided for, and retained only as long as the engagement requires.

Where we are today

We have not yet published formal third-party certifications.

We do not hold a published SOC 2 or ISO 27001 certification today. If your organization requires a specific compliance framework, or wants to review our controls in more detail before engaging us, tell us on the contact page and we will walk through what we have and what we are working toward.

Ask us about your requirements
Scroll to Top