Security and compliance

You hold the obligation, so you hold the controls.

You are the registrant. The recordkeeping obligation is yours. So the arrangement keeps everything we do inside your control and inside your examination record.

For your compliance consultant

This page is written to be forwarded. Every control has its own link, and the documentation behind them is available before an engagement starts.

  • No Arclength tenancy
  • Least privilege access
  • Written change log

The controls

Eight controls, stated in the engagement letter.

We hold no environment of our own that carries your data, we keep no copy of your records, and we appear on none of your invoices as a hosting cost. If we stop working together nothing has to move and nothing stops running.

Basis:
No Arclength tenancy

Anyone who touches your systems works from their own named account on your access register. Never a shared login and never a generic service account with a password in a document. Revocation takes effect the moment you make it, with no notice period and no call to us.

Basis:
Access register maintained by you

Our access is governed by the same rules as your staff accounts, so your offboarding process covers us without anyone having to remember. Where your policy requires multifactor, it is on.

Basis:
Delegated through your administration

The file is deleted when the task closes, and nothing goes to a personal device or an outside tool without written approval. Data is classified before anything is designed around it.

Basis:
Least privilege, no local copies

Most of what gets built runs inside the platforms you already license. Where a process genuinely cannot, anything it needs is provisioned in an account your firm owns, bills, and controls, with our access as a named administrator you can revoke. Nothing runs on infrastructure that would leave with us.

Basis:
Client owned account

Your compliance people can read the log at any time, and it is written to be legible to someone who was not in the room when the change was made.

Basis:
Written log per engagement

That covers unauthorized access, an automation that failed against client records, and anything else bearing on your books and records. You get what is known at the time and a written follow up as it develops.

Basis:
Written into the engagement letter

We carry errors and omissions and cyber liability cover at $1 million. What the confidentiality agreement covers, how long it runs, and how to obtain a certificate of insurance are all set out in the engagement letter before any credential is issued.

Basis:
Stated in the engagement letter

Due diligence

Documentation available on request.

Ask for any of these before an engagement starts and we will send it, with no call attached. We will also complete your vendor due diligence questionnaire and sign your information security addendum before access is granted.

  • The written scope for the engagement, including what is excluded from it
  • The access register format, showing what is recorded for every account we are granted
  • The change log format, showing how configuration changes are recorded and reviewed
  • The incident response procedure, including who is notified and in what order
A quiet modern office with glass partitions