Skip to content

UAE edition

What actually protects your books, stated plainly

A real status on every control, including the ones still in progress, not a polished list written to sound finished.

Short answer

Financial data belonging to a UAE client is treated as sensitive from the first login, not once a formal policy catches up. Least-privilege access and multi-factor authentication are already running, and any personal data reaching our delivery team moves only under contractual data protection terms consistent with the PDPL, Federal Decree-Law No. 45 of 2021. Nothing below is stated as more finished than it actually is.

The mechanics behind access and transfer

  • Access scoped to the role, not the person

    A team member reaches only the specific client files their role requires, never a single shared login covering the whole client base.

  • A written policy governs which devices touch client files

    Work happens under a stated device policy rather than on whatever laptop happens to be closest that day.

  • A signed agreement precedes any data movement

    Personal data does not reach our delivery team until contractual data protection terms are in place, covering confidentiality, access limits and use restricted strictly to the engagement you signed.

  • PDPL sets the retention and access baseline

    How long records are kept and how an access request gets handled follows Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, on top of our own internal handling policy.

Security

Controls and their current status

  • In place6
  • In progress7
  • Planned3
  1. Multi-factor authentication on client systems

    Every team member connecting to a client's accounting software, bank feed, or shared storage does so behind multi-factor authentication. Single-factor password access to client systems is not permitted under our internal access policy, regardless of role or tenure.

    Evidence: policy document

    In place
  2. Least-privilege access control

    Team members are granted access only to the specific client files and systems their engagement requires, not blanket access across the client base. Access is reviewed when an engagement ends or a role changes, and removed promptly rather than left open.

    Evidence: policy document

    In place
  3. No local storage of client files

    Client accounting data is worked on inside the client's own software (QuickBooks Online, Xero, or similar) or an approved shared workspace, not downloaded and saved to an individual team member's laptop or personal device. This limits how many places a client's financial data can end up.

    Evidence: policy document

    In place
  4. Signed non-disclosure agreement for every staff member

    Every team member with any access to client financial information signs a non-disclosure agreement before their first day on an engagement, covering client data specifically, not just general company confidentiality. This is a condition of employment, not an optional add-on for larger accounts.

    Evidence: policy document

    In place
  5. Full-disk encryption on team devices

    Laptops used to access client accounting systems run full-disk encryption, so a lost or stolen device does not expose readable client data. This is a baseline device requirement before any team member is granted client system access, not a later hardening step.

    Evidence: policy document

    In place
  6. Documented onboarding and offboarding for client access

    Every engagement follows a written checklist for granting access when a team member joins a client's books and revoking it when they leave the engagement or the company. This removes the common failure mode where a departed team member's access to a client's accounting software is simply forgotten.

    Evidence: policy document

    In place
  7. Written information security program (WISP)

    A written information security program aligned to IRS Publication 4557, covering administrative, technical, and physical safeguards for taxpayer and client financial data, is being drafted ahead of handling any US tax preparation data. A summary will be published once it is adopted, and no US tax data will be processed before it is in place.

    In progress
  8. Data processing agreement templates with SCCs and IDTA

    Standard Contractual Clauses for EU client data and a UK International Data Transfer Agreement, each paired with a transfer risk assessment, are being finalized with counsel to cover the cross-border transfer of client financial data from the UK and EU. These will be signed as part of onboarding for clients in those regions.

    In progress
  9. Section 7216 consent workflow for US tax data

    A written-consent workflow meeting the format required by Revenue Procedure 2013-14 is being built so that every US client explicitly consents, before any tax return information is disclosed, to that information being used and processed by our team. No US taxpayer data will be shared ahead of a signed consent.

    In progress
  10. Errors and omissions insurance

    A professional errors and omissions policy covering the firm's advisory and preparation-support work is in the process of being placed. We will not claim coverage is in force, or name a policy, until it is confirmed bound and the certificate is on file.

    In progress
  11. Cyber liability insurance

    A cyber liability policy covering data breach response for client financial data is in the process of being placed alongside our errors and omissions coverage. As with that policy, we will not claim coverage exists until it is confirmed bound.

    In progress
  12. Third-party software vendor review

    A documented review of the security posture of every software vendor in our stack, QuickBooks Online, Xero, and connected apps, is being formalized into a standing checklist run before any new tool is adopted for client work, rather than left to individual judgment.

    In progress
  13. Written incident response plan

    A documented, tested procedure for detecting, containing, and notifying clients of a security incident involving their data is being drafted alongside the written information security program. It will define notification timelines and responsibilities before it is relied on rather than after an incident occurs.

    In progress
  14. SOC 2 Type I examination

    We intend to engage an independent auditor for a SOC 2 Type I examination once the underlying controls above (WISP, incident response, vendor review, access management) are fully in place and operating, since a Type I report only has value once there is something real for the auditor to examine. No SOC 2 report exists today, and we will not use that language about ourselves until one is issued.

    Planned
  15. ISO 27001 certification

    ISO 27001 certification is a longer-term goal, particularly for UK and Australian clients where it carries more procurement weight, and would follow after SOC 2 readiness work is complete. No certification exists today and none is implied by any control listed above until it is actually issued.

    Planned
  16. Independent penetration test

    An independent, third-party penetration test of client-facing systems and internal tooling is planned as part of SOC 2 readiness work, to validate the access and encryption controls above rather than take them on faith. No test has been performed as of today, and none is claimed.

    Planned

Questions

What a UAE client typically wants confirmed

Is there a SOC 2 report we can review?

Not yet. An examination is planned, and we make no SOC 2 claim of any kind until a real, issued report actually exists to show you.

What actually governs data moving to the delivery team?

A signed agreement covering confidentiality, access limits and use restricted to the engagement, put in place before any data moves, consistent with what the PDPL expects of a data controller.

Where does our Xero, QuickBooks or Zoho Books data physically sit?

Inside the ledger your business already owns. Our team reaches it under least-privilege permissions and a written device policy, never by copying it somewhere else first.

Is multi-factor authentication actually enforced, or just recommended?

Enforced. Multi-factor authentication is required for any access to client accounting or banking systems, access is logged, and each login is tied to a specific person rather than a shared credential.

What happens to our data once an engagement ends?

Your Xero, QuickBooks Online or Zoho Books file was always yours and remains yours, since we never hold your books inside a system you cannot reach directly. Working files kept on our side, reconciliation notes and similar, are deleted on the schedule set out in our retention policy.

Can our own compliance team ask about a specific control in more depth?

Yes. Book a call and we will go through any control on this page in as much detail as your own review requires.

Who else touches your data

Sub-processors

This website is hosted on Vercel, in the United States, under contract with Northlane Solutions Inc.. The table below names every outside company that stores or transmits data on our behalf, what each one does, and where. The accounting work itself is performed by our team in Pakistan, inside your own software, per the No local storage of client files control above.

Data submitted through this site travels over TLS in transit and is stored encrypted at rest by our hosting and database providers.

  1. Vercel

    Website hosting and edge delivery

    Region: United States

    Data involved: Page requests, hosting and infrastructure logs

    Active today

  2. Supabase

    Stores information submitted through contact, quote and booking forms

    Region: Confirm in project settings

    Data involved: Name, email, phone, company and message content from forms

    Active today

  3. Resend

    Sends transactional email, such as confirming an enquiry arrived

    Region: United States

    Data involved: Name, email address and message content needed to send the email

    Active today

  4. Cloudflare

    Domain name resolution and inbound email routing for finbryn.com

    Region: Global network, United States-headquartered

    Data involved: DNS query metadata and routed email headers

    Active today

  5. Telegram

    Sends an internal alert to our team the moment a form is submitted

    Region: Distributed global infrastructure

    Data involved: Notification text only; the alert does not carry your full form submission or financial data

    Active today

  6. Vercel Web Analytics and Speed Insights

    Measures site traffic and page performance without placing a tracking cookie

    Region: United States

    Data involved: Aggregated, anonymized page-view and performance data; no cookies, no personal identifiers

    Active today

  7. Microsoft Clarity

    Session recordings and heatmaps to understand how visitors use the site, only where enabled

    Region: United States

    Data involved: Session interaction data, device and browser information; input fields are masked by default

    Only if enabled for this account

  8. Crisp

    Live chat widget for site visitors, only where enabled

    Region: European Union (Crisp IM SAS, France)

    Data involved: Chat messages, and name or email if you provide them

    Only if enabled for this account

  9. Tawk.to

    Live chat widget for site visitors, only where enabled as an alternative to Crisp

    Region: Multiple jurisdictions

    Data involved: Chat messages, and name or email if you provide them

    Only if enabled for this account

  10. Cal.com

    Hosts the call-booking calendar, only where a booking link is enabled

    Region: United States

    Data involved: Name, email, optional phone number, and the meeting time you select

    Only if enabled for this account

  11. WhatsApp (Meta)

    Click-to-chat messaging that you start, only where a WhatsApp link is enabled

    Region: United States (WhatsApp LLC, a Meta company)

    Data involved: Message content and phone number for the conversation you start

    Only if enabled for this account

List last updated: 2026-09-29

Next step

Bring your specific security questions to a call

Where a control here needs more detail for your own due diligence, we would rather walk through it directly than leave a gap on the page.