Skip to main content

How we protect your clients’ data.

You are responsible for your clients’ confidential information, and no outsourcing arrangement changes that. This page sets out exactly what we do, what we require of our people, what our agreements cover, and what we do not claim. If you need something here in writing for your own file, ask us and we will send it.

Your clients’ data stays in your systems.

This is the design decision everything else follows from. Your bookkeeper does not receive files to work on. They log into your accounting software, your document portal and your email system with their own named account, which you create and you can switch off in one click.

We do not host your clients’ data. We do not keep a copy of it. We do not have an administrator account on your systems. Nothing sits on our servers, because there is nothing for our servers to hold.

The practical consequence: if you ended the arrangement this afternoon, you would remove one user account and the data would never have moved.

The people.

  • Background verification before hire: identity, address, education and previous employment.
  • Reference checks with at least one previous employer.
  • A signed confidentiality and non-disclosure agreement, on joining, that covers your firm and your clients by name once you are a client.
  • Annual security and confidentiality training, with a written test they must pass.
  • A signed acceptable-use policy covering devices, email, cloud storage and personal accounts.
  • Access only to the clients you have specifically assigned. Nobody at tryACOwork browses your client list.
  • On leaving, access is revoked the same day and the confidentiality obligation continues indefinitely.

The access.

  • Named individual accounts only. No shared logins, ever, for any system.
  • You set the permission level, and we will tell you the minimum level the work needs so you can grant no more than that.
  • Multi-factor authentication on every account that supports it, and we will ask you to require it.
  • A password manager is mandatory for our team. Credentials are never shared over email or chat.
  • Access is reviewed with you every quarter, and we will send you the list of who has access to what.
  • Any access no longer needed is removed within one business day of the work ending.

The office and the machines.

  • Work happens only in our office, on company-owned machines. No personal laptops and no working from home on client data.
  • Access-controlled entry to the work area, and CCTV in common areas.
  • USB and external storage ports disabled at the operating system level.
  • Local file downloads and local saving blocked; cloud sync clients for personal accounts blocked.
  • Personal mobile phones are not permitted at the desk.
  • Printing is disabled by default and enabled only for a specific approved purpose.
  • Full disk encryption, managed antivirus, and enforced screen locking after five minutes.
  • Automatic operating system and browser updates, centrally managed.
  • A backup internet connection and backup power, so a local outage does not become your problem.

What you sign, and what it covers.

A service agreement between your firm and ours

Covers the scope of work, the fee, the notice period, confidentiality, data protection obligations, and our commitment not to subcontract any part of your work to another provider.

A confidentiality agreement covering your clients

Your bookkeeper and their team lead are individually bound in respect of your firm and your clients, not just in respect of us.

A data processing agreement, if you want one

Available on request, setting out what we process, on whose instruction, and for how long - which in our case is nothing retained. Useful if any of your clients have European or Californian data-protection obligations.

What the professional standards require of you.

This is a summary written to be useful, not legal advice. Confirm your own position with your professional adviser or your state board.

For bookkeeping work

The AICPA Code of Professional Conduct addresses the use of third-party service providers, principally at ET Section 1.150.040, which deals with informing the client that a third party may be used, and ET Section 1.700.040, which deals with either having a confidentiality agreement with the provider or obtaining the client’s specific consent. In broad terms, a firm using an outside provider is expected to inform its clients that a third-party provider may be used, and to take reasonable steps to ensure the provider maintains the confidentiality of client information. Most firms satisfy this with one sentence in the engagement letter and a confidentiality agreement with the provider. We can sign whatever confidentiality terms your firm requires, and we will sign both if you would prefer.

For your firm’s quality management system

Statements on Quality Management Standards No. 1 requires a firm’s system of quality management to address resources obtained from external providers. In practice that means the provider you use should be something your firm can describe, document and evidence, not just an arrangement that happens to exist. So we will give you a written supervision and confidentiality protocol you can put straight into your own file. It covers who reviews the work, how access is granted and removed, what we keep and for how long, and who to call if something goes wrong. Ask for it on the call and we will send it before you sign anything.

For tax return preparation

The rules are stricter. Internal Revenue Code Section 7216 makes unauthorised disclosure of tax return information an offence, and the regulations under it - Treasury Regulation Section 301.7216-3 - require the taxpayer’s signed consent before tax return information is disclosed to a preparer located outside the United States. For individual Form 1040 returns the IRS prescribes the exact consent wording, in Revenue Procedure 2013-14. We do not prepare tax returns, so this does not apply to our work - but if you are considering offshoring tax preparation to anyone, that consent requirement is the first thing to understand.

What never transfers

Responsibility for the work your firm issues stays with your firm. No provider can take it on, and any provider who implies otherwise is telling you something that is not true. Your bookkeeper prepares; you review, you decide, you sign. It is also why we publish a list of the things we will not do, on the Services page. If a piece of work would need us to reach a conclusion rather than prepare the file behind it, we will say so and decline it.

What does not apply to us

PCAOB registration requirements and the Form AP naming threshold apply to audits of public companies. That is not work we touch. If your firm audits public companies and you are considering offshore support for that work, those rules are the first thing to look at, and they sit outside what we do.

Wording you are welcome to use

We may use third-party service providers, including providers located outside the United States, to assist in performing bookkeeping and accounting services for you. We remain responsible for all services provided to you. We require any such provider to maintain the confidentiality of your information and to use it only for the purpose of performing services for our firm.

Copy that, put it in your engagement letter, and have your own adviser confirm it fits your state and your practice.

What we do not claim.

We are a young firm and we would rather tell you what we have not got than let you assume.

  • We do not hold a SOC 2 report yet.
  • We are not ISO 27001 certified.
  • We have not been audited by a third party against a security framework.
  • We do not claim a zero-incident history stretching back a decade, because we have not been operating for a decade.

What we can do is show you the office on a video call, walk you through the controls above, sign your confidentiality terms, and let you set the access level yourself. If a provider’s certification is a hard requirement for your firm or your insurer, tell us on the call and we will say plainly whether we meet it.

Book a 20-minute call

Questions about security.

Find out what one bookkeeper would do for your firm.

A 20-minute video call. We will tell you what it costs, how many of your clients one person could carry, and whether we are the right fit - including if we are not.