Your numbers are nobody's business but yours.
Before you hand anyone your books, your deal file, or your customer list, you deserve to know exactly how it will be treated. This page is that answer in plain language. The privacy policy carries the full legal version, and nothing here goes an inch past it.
Six commitments, every engagement
Encrypted, both directions
Your data is encrypted in transit, and the platforms that hold it encrypt it at rest under their own independent attestations. Nothing moves over an open line.
Read-only, and yours to revoke
We work from read-only access wherever possible. You grant it narrowly, we never move money or alter your ledger, and you can revoke it any day without a conversation.
Never used to train anything
Your files do your work and nothing else. Client data is never used to train any AI system, ours or anyone else's, and that is a condition we set, not a preference.
A person signs off
Machines do the heavy lifting here, and a human reviews client work before it ships. Nothing generated reaches you, your customers, or your file unread.
Confidential by default
Your deal, your numbers, and your customer list are shared with nobody. We sign a confidentiality agreement on request, before we see anything.
Deleted when you say so
When an engagement ends, we delete or return your data on request and confirm it in writing, keeping only what the law makes us keep.
Where your data actually lives
Mostly where it already lives today: in your own systems. The reporting work runs on accountant-style access to your accounting platform. The AI work runs inside the tools you already use wherever possible, through scoped connections you can see and cut. Deal work runs on documents you choose to send. We do not build a second copy of your business in somebody's warehouse.
Where a platform does hold data in an engagement, it is the boring, heavyweight kind: your accounting system, our payment processor, our scheduling and email providers. Those platforms carry their own independent security attestations, SOC 2 Type II and ISO 27001 among them, and their audit reports are public. We choose them partly for that. Our own practices ride on top and are listed in full in the privacy policy, including the short list of providers we share anything with and why.
The practices behind those commitments
Commitments are easy to write. These are the working habits underneath them, the same ones a security questionnaire asks about, stated plainly rather than as a checklist nobody reads.
- Two-factor authentication is required on every account that touches client work, so that a stolen password on its own opens nothing.
- Credentials belong in a password manager, never in a shared document, a spreadsheet, or an email thread. Where a system supports it, secrets are held by the operating system's own encrypted credential store rather than sitting in a config file.
- Full-disk encryption is required on every machine we work from, so that a lost or stolen laptop is an inconvenience rather than a disclosure.
- Access is granted narrowly and taken back. Read-only wherever the work allows, scoped to the one system that needs it, and dropped when the engagement ends. You can revoke it yourself, any day, without asking us first.
- Access to your systems is a named, revocable grant, never a permanent key. It expires, it is tied to a person rather than to a file, and you can withdraw it yourself in a couple of clicks. The kind of credential that leaks quietly and keeps working forever is not how we connect to you.
- Nothing secret goes in the codebase. No keys, no tokens, no client data in version control, checked rather than assumed.
- A written plan for the bad day. If a device or an account is ever compromised, who gets told and how quickly is decided in advance, not improvised while it is happening.
Contractual, not aspirational
These are contract terms, not website copy. The agreement you sign carries the confidentiality, data-handling, access and return obligations behind this page, so they are things you can hold us to rather than things we say. That is the part worth reading twice, and it is why this page lists practices rather than slogans.
Independent certification is on the roadmap as the practice grows, and the day it lands this page will say so with the report behind it. Until then, the controls above are what protect your data, the platforms holding it carry their own attestations, and the whole arrangement is in writing.
If your company's requirements call for a formal attestation from every vendor, raise it on the first call. We will tell you straight where we stand against your bar and where the work is better run inside your own systems. That answer costs nothing and it is worth having in thirty minutes rather than thirty days.
If you handle patient information
Med spas, clinics, and practices covered by HIPAA get a version of this built for them. Nobody can sell you a "HIPAA certificate"; there is no such thing. Compliance is a way of working, and ours is: patient records stay inside your compliant systems, we take the minimum data that does the job, and where your practice is covered by HIPAA we sign a business associate agreement before any file moves. Our med spa reactivation service, for example, runs on a minimal visit export with no names and no clinical notes, and every message to a client goes out under your practice's own authority.
If an engagement would touch protected health information directly, we scope that on the call, in writing, with your compliance obligations stated first. If a piece of work cannot be done inside those lines, we say so and do not do it.
What to keep out of forms and chat
Site forms and the chat widget are for questions, not for confidential material. Keep financial records, account credentials, and anything sensitive out of them. Inside an engagement, documents move through private channels we set up together, and your purchase confirmations name the exact method for anything you buy.
Ask us anything about this
Thirty minutes, free. Bring your security questions first if that is what stands between you and handing anyone your numbers. You will get straight answers from the people who do the work.
Book the free 30-minute callOr read the long versions: Privacy policy · Terms · How this firm runs
