KSA edition
The path your data travels, and the paperwork that permits it.
Stated as the controls actually stand today, including the ones still in progress.
Client financial data from Saudi Arabia is treated as sensitive the moment a login is created. Multi-factor authentication and least-privilege access are already running, a written security programme is being finished, and no personal data reaches our Pakistan-based delivery team until a data processing agreement covering the PDPL's transfer safeguards is signed.
Controls behind the transfer
Access scoped per role
A team member sees only the client files their role calls for. There is no single login that opens every account at once.
A device policy in writing
Client work happens under a documented device standard, not on whichever laptop is closest to hand.
A signed agreement before any transfer
A data processing agreement, covering the cross-border safeguards the PDPL requires, is signed before a single record from Saudi Arabia reaches our delivery team.
Retention set by the PDPL
How long we keep a record, how a request is handled, and what happens after a breach all follow the Personal Data Protection Law and SDAIA's guidance.
Security
Where each control actually stands
- In place6
- In progress7
- Planned3
Multi-factor authentication on client systems
Every team member connecting to a client's accounting software, bank feed, or shared storage does so behind multi-factor authentication. Single-factor password access to client systems is not permitted under our internal access policy, regardless of role or tenure.
Evidence: policy document
In placeLeast-privilege access control
Team members are granted access only to the specific client files and systems their engagement requires, not blanket access across the client base. Access is reviewed when an engagement ends or a role changes, and removed promptly rather than left open.
Evidence: policy document
In placeNo local storage of client files
Client accounting data is worked on inside the client's own software (QuickBooks Online, Xero, or similar) or an approved shared workspace, not downloaded and saved to an individual team member's laptop or personal device. This limits how many places a client's financial data can end up.
Evidence: policy document
In placeSigned non-disclosure agreement for every staff member
Every team member with any access to client financial information signs a non-disclosure agreement before their first day on an engagement, covering client data specifically, not just general company confidentiality. This is a condition of employment, not an optional add-on for larger accounts.
Evidence: policy document
In placeFull-disk encryption on team devices
Laptops used to access client accounting systems run full-disk encryption, so a lost or stolen device does not expose readable client data. This is a baseline device requirement before any team member is granted client system access, not a later hardening step.
Evidence: policy document
In placeDocumented onboarding and offboarding for client access
Every engagement follows a written checklist for granting access when a team member joins a client's books and revoking it when they leave the engagement or the company. This removes the common failure mode where a departed team member's access to a client's accounting software is simply forgotten.
Evidence: policy document
In placeWritten information security program (WISP)
A written information security program aligned to IRS Publication 4557, covering administrative, technical, and physical safeguards for taxpayer and client financial data, is being drafted ahead of handling any US tax preparation data. A summary will be published once it is adopted, and no US tax data will be processed before it is in place.
In progressData processing agreement templates with SCCs and IDTA
Standard Contractual Clauses for EU client data and a UK International Data Transfer Agreement, each paired with a transfer risk assessment, are being finalized with counsel to cover the cross-border transfer of client financial data from the UK and EU. These will be signed as part of onboarding for clients in those regions.
In progressSection 7216 consent workflow for US tax data
A written-consent workflow meeting the format required by Revenue Procedure 2013-14 is being built so that every US client explicitly consents, before any tax return information is disclosed, to that information being used and processed by our team. No US taxpayer data will be shared ahead of a signed consent.
In progressErrors and omissions insurance
A professional errors and omissions policy covering the firm's advisory and preparation-support work is in the process of being placed. We will not claim coverage is in force, or name a policy, until it is confirmed bound and the certificate is on file.
In progressCyber liability insurance
A cyber liability policy covering data breach response for client financial data is in the process of being placed alongside our errors and omissions coverage. As with that policy, we will not claim coverage exists until it is confirmed bound.
In progressThird-party software vendor review
A documented review of the security posture of every software vendor in our stack, QuickBooks Online, Xero, and connected apps, is being formalized into a standing checklist run before any new tool is adopted for client work, rather than left to individual judgment.
In progressWritten incident response plan
A documented, tested procedure for detecting, containing, and notifying clients of a security incident involving their data is being drafted alongside the written information security program. It will define notification timelines and responsibilities before it is relied on rather than after an incident occurs.
In progressSOC 2 Type I examination
We intend to engage an independent auditor for a SOC 2 Type I examination once the underlying controls above (WISP, incident response, vendor review, access management) are fully in place and operating, since a Type I report only has value once there is something real for the auditor to examine. No SOC 2 report exists today, and we will not use that language about ourselves until one is issued.
PlannedISO 27001 certification
ISO 27001 certification is a longer-term goal, particularly for UK and Australian clients where it carries more procurement weight, and would follow after SOC 2 readiness work is complete. No certification exists today and none is implied by any control listed above until it is actually issued.
PlannedIndependent penetration test
An independent, third-party penetration test of client-facing systems and internal tooling is planned as part of SOC 2 readiness work, to validate the access and encryption controls above rather than take them on faith. No test has been performed as of today, and none is claimed.
Planned
Questions
What Saudi Arabia clients ask about data
Has Finbryn completed a SOC 2 examination?
Not yet. One is planned, and we will not claim SOC 2 status until an actual report exists to show you.
Where does data from my Zoho Books, QuickBooks or Xero account actually sit?
Inside the ledger you already control. Our team reaches it under scoped, logged access, never through a copy held on our own systems.
What legal instrument covers moving my data outside the Kingdom?
A data processing agreement, signed with you ahead of the transfer, built around the cross-border safeguards the PDPL requires for data leaving Saudi Arabia.
Can your team walk my compliance function through this in more depth?
Yes, book a call and we will go through any control on this page for as long as your review needs.
What becomes of our data once the engagement ends?
Your accounting file was never ours to begin with, so it stays fully yours. Any notes or working files kept on our side are removed on the schedule set out in our retention policy.
Is access to banking and accounting systems logged?
Yes. Multi-factor authentication is required, every access is logged against a named person rather than a shared credential, and that log records who reached what and when.
Who else touches your data
Sub-processors
This website is hosted on Vercel, in the United States, under contract with Northlane Solutions Inc.. The table below names every outside company that stores or transmits data on our behalf, what each one does, and where. The accounting work itself is performed by our team in Pakistan, inside your own software, per the No local storage of client files control above.
Data submitted through this site travels over TLS in transit and is stored encrypted at rest by our hosting and database providers.
Website hosting and edge delivery
Region: United States
Data involved: Page requests, hosting and infrastructure logs
Active today
Stores information submitted through contact, quote and booking forms
Region: Confirm in project settings
Data involved: Name, email, phone, company and message content from forms
Active today
Sends transactional email, such as confirming an enquiry arrived
Region: United States
Data involved: Name, email address and message content needed to send the email
Active today
Domain name resolution and inbound email routing for finbryn.com
Region: Global network, United States-headquartered
Data involved: DNS query metadata and routed email headers
Active today
Sends an internal alert to our team the moment a form is submitted
Region: Distributed global infrastructure
Data involved: Notification text only; the alert does not carry your full form submission or financial data
Active today
Vercel Web Analytics and Speed Insights
Measures site traffic and page performance without placing a tracking cookie
Region: United States
Data involved: Aggregated, anonymized page-view and performance data; no cookies, no personal identifiers
Active today
Session recordings and heatmaps to understand how visitors use the site, only where enabled
Region: United States
Data involved: Session interaction data, device and browser information; input fields are masked by default
Only if enabled for this account
Live chat widget for site visitors, only where enabled
Region: European Union (Crisp IM SAS, France)
Data involved: Chat messages, and name or email if you provide them
Only if enabled for this account
Live chat widget for site visitors, only where enabled as an alternative to Crisp
Region: Multiple jurisdictions
Data involved: Chat messages, and name or email if you provide them
Only if enabled for this account
Hosts the call-booking calendar, only where a booking link is enabled
Region: United States
Data involved: Name, email, optional phone number, and the meeting time you select
Only if enabled for this account
Click-to-chat messaging that you start, only where a WhatsApp link is enabled
Region: United States (WhatsApp LLC, a Meta company)
Data involved: Message content and phone number for the conversation you start
Only if enabled for this account
List last updated: 2026-09-29
Next step
Bring your due-diligence questions to a call
A gap on this page is worth a conversation, not a guess on your end.