What we claim,
and what we don't
Most firms in this category lead with certification badges. Below is a straight account of the controls we actually run, the standards we are aligned to, and the ones we are not yet certified against - because you should be able to tell the difference.
The honest version
Security pages in this industry tend to be a wall of logos. It is worth knowing what those logos mean, because aligned to, compliant with and certified against are three very different statements and they are routinely used as if they were one.
So, plainly:
- ISO 27001 - aligned, not certified. We operate an information security management framework built on the ISO 27001 control set across every engagement. We have not completed a third-party certification audit, and we do not claim to have one. If you need a certified provider for procurement reasons, tell us early and we will say so rather than waste your time.
- GDPR and UK GDPR - compliant. EU and UK personal data is processed under GDPR standards, with a data processing agreement available before any data moves.
- SOC 2 - not held. Some larger providers in this market hold SOC 2 Type 2 reports. We do not. That is a genuine difference between us and a 1,000-person firm, and you should weigh it.
What we do have is a small, named, fully accountable team, controls that are actually enforced rather than documented, and a founder whose professional licences are on the line for every file. For most of the businesses we work with, that trade is the right one. For some, it is not - and we would rather you knew that now.
Where your data actually sits
In your systems, overwhelmingly. We work inside your QuickBooks, Xero, NetSuite, CaseWare or tax software under named users with role-based permissions. We do not migrate you onto a platform of ours, and we do not build a shadow copy of your ledger.
Where documents have to move - source files, workpapers, deliverables - they move through your portal where you have one, or through controlled cloud storage with access logging where you do not. Email is not used as a file transfer mechanism for client data.
If the engagement ends, there is very little to unwind: your ledger was always yours, and our access is removed. We retain only what our professional and legal obligations require, for the period they require it.
The people, not just the systems
Most breaches in this industry are not technical. They are a person emailing the wrong file to the wrong client, or an ex-employee whose access was never revoked.
That is why access reviews happen quarterly rather than annually, why access is removed on the day someone leaves an engagement rather than at the next review, and why every deliverable passes through a second reviewer before it is sent. The two-tier review exists for quality, but it catches misdirected work as well.
Every control we actually run
Not aspirational. If something on this list is not true of your engagement from day one, tell us and we will fix it.
| Area | Control |
|---|---|
| Access | Named user accounts Every team member accesses your systems under their own named account with role-based permissions. No shared logins, ever - which means every action in your ledger is attributable to a person. |
| Access | Multi-factor authentication MFA is required on every system that touches client data, including our own email and file storage. |
| Network | VPN-only connections All connections to client systems run through an encrypted VPN. Client systems are never accessed from an open network. |
| Device | No external storage USB and external storage are disabled on the delivery floor. Personal mobile devices are not permitted in the delivery area. |
| Device | No local client data Client data is not stored on local machines. Work happens in your systems or in controlled cloud storage with access logging. |
| Contract | NDA before anything A mutually binding non-disclosure agreement is signed before any system access or data transfer. We will sign yours instead of ours if you prefer. |
| Monitoring | Activity logs & access reviews Complete activity logging with quarterly access reviews - including removing access promptly when someone leaves an engagement or the firm. |
| Process | Two-tier review A preparer and a CPA or CA review every deliverable. The second pair of eyes is a control, not a courtesy. |
Your Data.
Locked Down.
Always.
We handle your most sensitive financial information with the same discipline used at MNC banking environments. No shortcuts. No exceptions.
ISO 27001 Aligned
Information security management framework adopted across all engagements.
GDPR Compliant
EU data protection standards followed for all UK and European clients.
NDA-First
Every engagement begins with a strict, mutually-binding non-disclosure agreement.
USB Restricted
External storage and personal mobiles disabled on the secure delivery floor.
VPN-Only Access
Encrypted connections to all client systems with multi-factor authentication.
Audit Trails
Complete activity logs and quarterly access reviews for full transparency.
Asked by every
procurement team.
If your own security questionnaire needs completing, send it - we fill them in rather than returning a brochure.
Will you sign our NDA and data processing agreement?
Yes, and we would prefer to sign yours than ask you to sign ours. We have a standard mutual NDA and DPA available if you do not have your own, and we will execute either before any system access or data transfer.
Are you ISO 27001 certified?
No. We are aligned to the ISO 27001 control set and operate the controls listed on this page, but we have not completed a third-party certification audit and do not claim certification. If certification is a hard procurement requirement for you, we are not the right provider and we will tell you that on the first call rather than the fifth.
Do you carry professional indemnity or cyber liability cover?
Ask on the call and we will tell you exactly what is in place and share the certificate. We would rather give you a current, specific answer than publish a figure here that drifts out of date.
Where is the delivery team located?
India, working from a controlled delivery floor with restricted external storage and no personal devices in the work area. Registered offices are in New York and Surat, Gujarat.
What happens to our data if we stop working with you?
Our access is revoked. Because we work inside your systems rather than duplicating them, there is very little to return - your ledger was always in your subscription. We retain only what professional and legal obligations require, for as long as they require it, and we will confirm that in writing at the end of the engagement.
Can you complete our security questionnaire?
Yes. Send it through and we will complete it properly, including the questions where the honest answer is "we do not have that." A questionnaire with a few clear negatives is more useful to you than one where everything is a yes.
Send us your security questionnaire.
We complete them properly, including the questions where the honest answer is no.