Security & confidentiality

Two things you are trusting us with

Your clients' financial data, and your relationship with those clients. What follows is what we actually do today — not a list of certifications we are working towards.

The work is done in Canada

The people with access to your files are in Canada. Where the data itself lives is a separate question and worth being precise about: your ledger sits wherever your QuickBooks, Xero or Sage subscription sits, exactly as it does today without us. What we are telling you is who is doing the work, not that we have moved your data anywhere.

The ledger stays yours

Your firm or your client owns the QuickBooks, Xero or Sage subscription. We are added as a user at the permission level you set, on the files you choose. You can see exactly what we can reach, and you can remove that access yourself at any time without asking us.

A separate workspace per firm

Source documents move through a dedicated, access-controlled workspace we set up for your firm alone — never shared with another client of ours, and never through personal email accounts or messaging apps.

Nothing on personal devices

Client records are worked on through managed systems. They are not downloaded to personal laptops or phones, and they do not sit in someone’s downloads folder after the period closes.

Confidentiality in writing

Every engagement is covered by a signed confidentiality agreement that includes a non-solicitation commitment covering your clients. Ask to see it before you move a file, not after.

A clean exit

When an engagement ends, our access is revoked and the working files are returned to your firm. Nothing about the arrangement is designed to make leaving difficult.

The one that matters most

We will not approach your clients. Ever.

This is the question every firm owner asks, usually about ninety seconds into the first call, and it deserves a direct answer rather than reassurance. We do not contact your clients, we do not market to them, and we do not accept work from them — during the engagement or after it ends. It is a written non-solicitation term in our agreement, not a promise made over the phone.

The commercial logic is straightforward: our entire business depends on firms being willing to put us in front of their books. A single instance of poaching would end that, permanently and deservedly.

Working practices

How access actually works

  • You invite us into the ledger yourself, at the permission level you choose.
  • You can see what we can reach, and revoke it at any time without asking us.
  • Source documents move through a workspace set up for your firm alone.
  • Nothing travels through personal email accounts or messaging apps.
  • On offboarding, access is revoked and working files are returned to your firm.

Ask us for the details

If your firm has a vendor due-diligence process, a client with specific data-handling requirements, or an insurer that wants specifics, raise it on the first call. We would rather answer precisely than have you assume.

Ask us the hard questions first.

Bring your due-diligence checklist to the first call. Every question about data handling, confidentiality and non-solicitation gets a direct answer before you move a single file.