Confidentiality & Data Security
Your ledgers, payroll, tax records and plans are among the most sensitive things your business owns. This page sets out, in plain terms, how we protect them: before, during and after every engagement.
Confidentiality is a professional duty, not a marketing promise
As Chartered Accountants we are bound by the confidentiality principle of the ICAP Code of Ethics, which follows the international IESBA Code. It forbids us from disclosing client information without proper authority, or using it for anyone’s advantage: including our own. That duty continues after an engagement ends.
Professional basis: ICAP Code of Ethics for Chartered Accountants (IESBA-based) · Confidentiality terms in every engagement letter · Mutual NDA available on request
Signed before we start
Every engagement letter carries binding confidentiality terms. If you would like an NDA before sharing anything for a proposal, we will sign yours or provide ours: before the first detailed conversation.
Everyone on your file is bound
All team members sign individual confidentiality undertakings on joining, and these obligations survive the end of their employment.
Need-to-know only
Only the people assigned to your engagement can see your information. Your data is never shared with, or visible to, other clients.
How we protect your information, layer by layer
Security is not one tool. It is people, access, systems and process working together: so a single slip does not become a breach.
People
Background and reference checks before hiring, signed confidentiality undertakings, and regular training on data handling, phishing and payment-fraud scams. Access is removed the same day someone leaves or rotates off your file.
Access
Named-user accounts only: no shared logins. Multi-factor authentication on every system that holds client data. Least-privilege, role-based permissions, reviewed regularly.
Your systems, your control
Where possible we work inside your own cloud accounting, ERP and banking platforms using users you create and can revoke at any time. We use view-only access to bank accounts unless you ask otherwise, and we never ask for your passwords.
Secure exchange
Documents are exchanged through encrypted, access-controlled client folders or portals: not open email attachments or messaging apps. Sensitive files can be password-protected, with the password sent through a separate channel.
Devices & storage
Firm-managed devices with full-disk encryption, screen locks, up-to-date security software and remote-wipe. Client files live in business-grade encrypted cloud storage: not on personal devices or USB drives.
Third parties & AI
We use only reputable, business-grade providers under confidentiality terms. Client data is never pasted into public AI tools; any AI we use runs on business plans where your data is not used to train models.
What happens to your information at every stage
Before engagement
NDA on request. We ask only for what we need to scope the work: no bulk data before a signed engagement letter.
Onboarding
We agree who at your end can send and approve information, set up a secure folder, and request named-user access to your systems.
During the work
Data stays in your systems or our encrypted workspace. Every deliverable is reviewed by a partner before it reaches you, and goes only to agreed contacts.
After we finish
Your system access is removed. Your original records are returned. Working papers are kept only for the period required by law and professional standards, then securely destroyed.
Our standing promises
- Put confidentiality in writing in every engagement.
- Confirm unusual payment or bank-detail change requests by phone before acting: to protect you from invoice fraud.
- Tell you promptly if we ever believe your information has been exposed, what happened and what we are doing about it.
- Answer your security questions (or your vendor due-diligence questionnaire) before you share anything.
- Handle personal data (payroll, employee and customer records) in line with applicable data-protection laws, and sign a data processing agreement where your law requires one (for example, UK or EU GDPR).
Lines we don’t cross
- Share your information with anyone without your consent, except where the law requires it.
- Name you as a client, or use your work in case studies or references, without written permission.
- Ask for your passwords, OTPs or banking PINs: by email, phone or chat.
- Put your data into public AI tools or use it to train any model.
- Keep your files on personal devices, or share them between clients.
- Keep your data longer than the law and professional standards require.
When the law requires disclosure. Like every regulated accountant, we may have to share information when compelled by law: for example a tax authority notice, a court order or anti-money-laundering obligations. When this happens, we disclose only what is strictly required and, where we are legally allowed to, we tell you first.
Confidentiality FAQs
Will you sign our NDA before we share anything?
Yes. We are happy to sign your NDA (or provide a mutual one) before any detailed discussion or document exchange, at no cost.
Where is our data stored?
Wherever possible it stays in your own systems. Files we hold are kept in business-grade, encrypted cloud storage from established providers. If you have a data-residency requirement, tell us at the proposal stage and we will confirm how we can meet it.
Who at your firm can see our information?
Only the named people assigned to your engagement, and the reviewing partner. We will tell you who they are, and you can ask for an access list at any time.
Do you need our banking or system passwords?
No. We never ask for your passwords. You create a named user for us with only the permissions the work needs (view-only for banking unless agreed otherwise) and you can remove it at any time.
Do you use AI with our data?
Never with public or consumer AI tools. Where we use AI to improve speed or accuracy, it runs on business plans under which your data is not used for training, and every output is reviewed by a qualified accountant.
What happens to our records when the engagement ends?
We remove our access to your systems, return your original documents, and keep only the working papers we are legally and professionally required to retain. These are held securely for that period and then destroyed.
What if a team member leaves?
Their access is revoked the same day, firm devices are recovered or wiped, and their confidentiality undertaking continues to bind them after they leave.
Can you complete our vendor security questionnaire?
Yes. Send it with your enquiry and we will return it with our proposal.
Questions about security? Ask before you share.
Tell us your concerns first: we will answer them, sign your NDA, and only then ask for information.