Security
Security & compliance
Handing someone access to your financial data is an act of trust.
Our security practices
Handing someone access to your financial data is an act of trust. Here's specifically what we do to earn it.
- Confidentiality agreements
- Every engagement opens with a signed NDA and confidentiality agreement covering individual team members, not just the company.
- Encryption in transit and at rest
- Data is encrypted both in transit and at rest, and stored in access-controlled cloud environments rather than on local devices.
- Multi-factor authentication
- Every system that touches client data is reachable only through multi-factor authentication, with strong password policies enforced.
- Role-based access
- Access is limited to the people actually working on your account, and revoked immediately when a role changes or an engagement ends.
- Controlled file transfer
- Files move through encrypted, access-controlled channels rather than email attachments.
- Backups
- Working data is backed up on a regular schedule, so a single failure is never a single point of loss.
- GDPR-aligned handling
- For UK and EU-connected clients, our data handling is built around GDPR's core principles: data minimisation, purpose limitation, and secure storage.
We describe the practices we actually operate. We do not claim a formal certification such as SOC 2, ISO 27001 or HIPAA, because we have not completed those processes — and on a page about trust, an unearned badge is worse than none. If your procurement process requires a specific standard, tell us and we will answer honestly about where we stand.
Ask us a security questionGet started
Ready to stop chasing your own books?
Book a free, no-obligation call and get a written read on where your finance function stands today.
Thirty minutes · No obligation · Free financial health review
