How we handle your data
Automating your back office means giving us access to your books, your customers and sometimes your payroll. These are the rules we follow on every job. They go into the engagement letter, so you can hold us to them.
We never ask for your password
You add us as a user in your own QuickBooks, Xero, Google Workspace or Microsoft 365, with our own login. Every action we take is recorded under our name in your tools' own history.
We take the least access each job needs
Read-only during the review. During a build, only the permissions that automation needs, and nothing in systems it doesn't touch. We tell you what we've asked for and why.
Our own accounts are locked down
Two-factor sign-in on every account we use for client work. Any credentials an automation needs are kept in an encrypted password vault, never in email, chat or spreadsheets.
Your data doesn't train anyone's AI
Some automations use AI to read documents like invoices or timesheets. Those go through business AI services whose terms say they don't train on your data. We send only the document being read, and nothing gets posted to your books on the AI's word alone. Rules check it, or a person approves it.
You know where everything runs
Wherever possible, automations run inside your own accounts. When something has to run elsewhere, we tell you in writing where, before we build it, and it stays in Canada or the US.
A person approves the unusual
Automations handle routine cases. Anything new, anything that doesn't add up and anything over a limit you set waits for someone on your team. Every automation keeps a log of what it did.
Confidential means confidential
We'll sign your confidentiality agreement, or offer ours, before the review starts. We don't name clients or describe their work without written permission.
Leaving is clean
Remove our user and our access is gone. Everything we built stays in your accounts, written up. We delete any copies of your data we held within 30 days and confirm it in writing.
If something goes wrong, you hear from us
If we find a security problem affecting your data, we tell you within 72 hours of finding it, with what happened and what we're doing about it.
What we don't claim
We're a small firm. We don't have a SOC 2 report or an ISO certificate, and we won't pretend to. What we have is the short list above, followed on every job and written into your agreement.
If your business does need a formal security review, for example because of a lender, an insurer or a large customer, tell us on the first call. We'll answer your questionnaire honestly, item by item.
Security questions
- Will you see our bank account?
- Usually only through the bank feed already connected to your accounting software. We don't ask for online banking access, and we never move money.
- What happens to our data if you stop working with us?
- It stays in your tools, where it always was. Any working copies we held are deleted within 30 days, and we confirm that in writing.
- Can our accountant see what you've done?
- Yes. Everything we do in your books is recorded in its own history under our user, and we're happy to walk your accountant through any automation.
- Does our customer information leave our systems?
- Only as far as an automation needs to pass it from one of your tools to another. We don't keep a separate copy, and we never use it for anything else.
Have a chore like this?
Book a free 20-minute call. We'll tell you whether it's worth automating and roughly what it would cost. If it isn't worth it, we'll say so.
Pick a time