Security & confidentiality
Client financial data is the core of what we handle. Here is what we actually do to keep it controlled, and where we are still building out formal certification.
Access & infrastructure
Delivery work is done through virtual desktop (VDI) access rather than on individual laptops, so client files and systems are not copied onto local machines. Access is role-based, so team members see only the systems and records their engagement requires.
Work happens inside a controlled virtual environment, not on personal devices.
Access to client systems and files is scoped to what each engagement needs.
Data in transit and at rest is encrypted as standard practice across engagements.
People & process
Team members working on client engagements operate under confidentiality obligations, and engagements are scoped up front so access is limited to the people actually doing the work, not the wider team.
Staff working on client data operate under confidentiality obligations as a condition of the engagement.
Each engagement defines who touches which systems and records before work starts.
Client data is used only for the engagement it was provided for, and retained only as long as the engagement requires.
Where we are today
We do not hold a published SOC 2 or ISO 27001 certification today. If your organization requires a specific compliance framework, or wants to review our controls in more detail before engaging us, tell us on the contact page and we will walk through what we have and what we are working toward.
Ask us about your requirements