Trusted by Intuit · SaaS Direct United States 🇺🇸Book a Discovery Call →

Security & Compliance

Your client data never leaves your environment

Our teams work inside your systems through controlled remote access. No local downloads, no data at rest on offshore machines, no shadow copies. You keep custody of the data and you keep the audit trail.

A one-page summary your prospect’s IT reviewer can read without you in the room.

How access actually works

Most security pages show you a badge. This one shows you the architecture, because the badge is not what your IT reviewer is really asking about.

1 · The person

A background-verified team member on an access-controlled delivery floor. No personal devices, no removable media, clean-desk enforced.

2 · The gate

Your identity provider, your MFA, your conditional access policy. We do not issue the credential. You do, and you can revoke it in seconds without contacting us.

3 · The session

A hardened virtual desktop or your VPN. Local drives, USB, printing, clipboard transfer and screen capture disabled by policy and by technical control.

4 · The data

Stays where it already was: in your systems, under your retention policy, in your audit log. Nothing is copied to an offshore environment at any point.

The one sentence that matters

Because the data never moves, the offshore team is a remote user of your environment, not a recipient of your data. That distinction is what your IT reviewer, your insurer and your peer reviewer all care about, and it is the reason this model passes review when file-transfer models do not.

Frameworks we work to

The scope each one covers, and the documentation you can request. Nothing on this list is a badge we cannot back up.

FrameworkStatus & scopeEvidence available
GDPRCompliance programme covering UK and EU engagements, including data processing agreements and standard contractual clauses where transfers apply.DPA template and SCC pack on request
IRS Publication 4557Safeguards aligned to Pub 4557 for US tax engagements, mapped to your firm’s Written Information Security Plan.Mapping document provided at onboarding
IRC §7216Consent process and compliant template for disclosure of taxpayer information to a preparer outside the United States.Consent template and guidance provided

Personnel

Who is on the other end

Technical controls stop the wrong access. Personnel controls stop the wrong person. Both are required, and most security pages only talk about the first.

Pre-assignment verification

Identity, education, employment history and criminal record verification completed before any team member is assigned to a client account. Re-verified on a defined cycle.

Individual confidentiality agreements

Each team member signs a personal confidentiality agreement, not just a company-level NDA. The obligation follows the individual and survives their employment.

Least-privilege by role

Access is scoped to the minimum the role requires, documented at provisioning, reviewed quarterly, and revoked same-day on role change or departure.

Security training

Induction training on data handling, phishing and client confidentiality, refreshed annually. Records available for your peer review file.

Independence confirmations

For audit and assurance engagements, every team member completes your firm’s independence confirmation before assignment and on engagement change.

Conflict register

We maintain a conflict-check register and will not staff an individual across engagements where your firm’s policy prohibits it.

Physical and facility controls

Our delivery centres are in Gurugram and Kolkata, India, with client-facing leadership in the US. Teams serve clients across the US, UK, Canada, the Netherlands, Germany, Cyprus, Curacao, South Africa and Australia.

Access-controlled floors

Badge-controlled entry to delivery areas, segregated by client where engagement terms require it. Visitor logging and escort policy enforced.

Monitored environment

CCTV coverage of operations floors with defined retention. Incident logging and review process documented.

Clean desk, no devices

No personal phones, cameras or removable media on the operations floor. Paper output controlled, clean-desk policy enforced and audited.

Your side of the line

What a US firm has to do, and what we provide

Outsourcing does not transfer your regulatory obligations. It does mean you should not have to build the documentation yourself.

Your obligationWhat we provide
IRC §7216 consentA compliant written consent template, guidance on when it applies and when it does not, and format requirements for electronic consent.
Written Information Security PlanA control mapping showing how our controls satisfy the third-party service provider sections of your WISP.
IRS Pub 4557 safeguardsDocumented alignment of our technical, personnel and physical controls to the Pub 4557 safeguard categories.
Peer review documentationCredential records, training records, independence confirmations and the access register, in the format your peer reviewer expects.
Client engagement lettersSuggested language covering the use of third-party delivery resources, for your counsel to review and adapt.
Professional liability disclosureOur insurance certificates and the contractual liability position, so your broker can assess it.

Security summary

The one-page summary your prospect’s IT reviewer asks for

Controls, data residency, access model, and the audit questions we already have answers to. Ask us on the scoping call and we will send it the same day.

Bring your IT reviewer to the call.

Most firms want their technical people to hear this directly. We would rather answer the hard questions early than discover them at contract stage.