Your client data never leaves your environment
Our teams work inside your systems through controlled remote access. No local downloads, no data at rest on offshore machines, no shadow copies. You keep custody of the data and you keep the audit trail.
A one-page summary your prospect’s IT reviewer can read without you in the room.
How access actually works
Most security pages show you a badge. This one shows you the architecture, because the badge is not what your IT reviewer is really asking about.
1 · The person
A background-verified team member on an access-controlled delivery floor. No personal devices, no removable media, clean-desk enforced.
2 · The gate
Your identity provider, your MFA, your conditional access policy. We do not issue the credential. You do, and you can revoke it in seconds without contacting us.
3 · The session
A hardened virtual desktop or your VPN. Local drives, USB, printing, clipboard transfer and screen capture disabled by policy and by technical control.
4 · The data
Stays where it already was: in your systems, under your retention policy, in your audit log. Nothing is copied to an offshore environment at any point.
The one sentence that matters
Because the data never moves, the offshore team is a remote user of your environment, not a recipient of your data. That distinction is what your IT reviewer, your insurer and your peer reviewer all care about, and it is the reason this model passes review when file-transfer models do not.
Frameworks we work to
The scope each one covers, and the documentation you can request. Nothing on this list is a badge we cannot back up.
| Framework | Status & scope | Evidence available |
|---|---|---|
| GDPR | Compliance programme covering UK and EU engagements, including data processing agreements and standard contractual clauses where transfers apply. | DPA template and SCC pack on request |
| IRS Publication 4557 | Safeguards aligned to Pub 4557 for US tax engagements, mapped to your firm’s Written Information Security Plan. | Mapping document provided at onboarding |
| IRC §7216 | Consent process and compliant template for disclosure of taxpayer information to a preparer outside the United States. | Consent template and guidance provided |
Personnel
Who is on the other end
Technical controls stop the wrong access. Personnel controls stop the wrong person. Both are required, and most security pages only talk about the first.
Pre-assignment verification
Identity, education, employment history and criminal record verification completed before any team member is assigned to a client account. Re-verified on a defined cycle.
Individual confidentiality agreements
Each team member signs a personal confidentiality agreement, not just a company-level NDA. The obligation follows the individual and survives their employment.
Least-privilege by role
Access is scoped to the minimum the role requires, documented at provisioning, reviewed quarterly, and revoked same-day on role change or departure.
Security training
Induction training on data handling, phishing and client confidentiality, refreshed annually. Records available for your peer review file.
Independence confirmations
For audit and assurance engagements, every team member completes your firm’s independence confirmation before assignment and on engagement change.
Conflict register
We maintain a conflict-check register and will not staff an individual across engagements where your firm’s policy prohibits it.
Physical and facility controls
Our delivery centres are in Gurugram and Kolkata, India, with client-facing leadership in the US. Teams serve clients across the US, UK, Canada, the Netherlands, Germany, Cyprus, Curacao, South Africa and Australia.
Access-controlled floors
Badge-controlled entry to delivery areas, segregated by client where engagement terms require it. Visitor logging and escort policy enforced.
Monitored environment
CCTV coverage of operations floors with defined retention. Incident logging and review process documented.
Clean desk, no devices
No personal phones, cameras or removable media on the operations floor. Paper output controlled, clean-desk policy enforced and audited.
Your side of the line
What a US firm has to do, and what we provide
Outsourcing does not transfer your regulatory obligations. It does mean you should not have to build the documentation yourself.
| Your obligation | What we provide |
|---|---|
| IRC §7216 consent | A compliant written consent template, guidance on when it applies and when it does not, and format requirements for electronic consent. |
| Written Information Security Plan | A control mapping showing how our controls satisfy the third-party service provider sections of your WISP. |
| IRS Pub 4557 safeguards | Documented alignment of our technical, personnel and physical controls to the Pub 4557 safeguard categories. |
| Peer review documentation | Credential records, training records, independence confirmations and the access register, in the format your peer reviewer expects. |
| Client engagement letters | Suggested language covering the use of third-party delivery resources, for your counsel to review and adapt. |
| Professional liability disclosure | Our insurance certificates and the contractual liability position, so your broker can assess it. |
Security summary
The one-page summary your prospect’s IT reviewer asks for
Controls, data residency, access model, and the audit questions we already have answers to. Ask us on the scoping call and we will send it the same day.
Bring your IT reviewer to the call.
Most firms want their technical people to hear this directly. We would rather answer the hard questions early than discover them at contract stage.
