Skip to content

UK edition

Where your accounts data travels, and under what agreement.

Real controls, stated as they actually stand today, not as a finished list of certifications.

Short answer

Finbryn treats UK client financial data as sensitive from the first login. A written information security programme is in progress, least-privilege access and multi-factor authentication are already in place, and a UK International Data Transfer Agreement, with a transfer risk assessment, is signed with you before any UK personal data reaches our Pakistan-based team. The list below is honest about what is finished and what is not.

How access and transfers are handled

  • Least-privilege access

    Each team member reaches only the client files their role needs, rather than one shared login covering everything.

  • A written device policy

    Client files are worked on under a stated device policy, not on whatever personal machine happens to be nearby.

  • The UK IDTA governs the transfer

    Personal data reaching our Pakistan-based team travels only once a UK International Data Transfer Agreement (UK IDTA), the mechanism UK GDPR sets out for moving data outside the UK, is signed with you.

  • Records kept under the Data Protection Act 2018

    Retention, access requests and breach handling follow UK GDPR and the Data Protection Act 2018, alongside guidance from the Information Commissioner's Office.

Security

Controls and their current status

  • In place6
  • In progress7
  • Planned3
  1. Multi-factor authentication on client systems

    Every team member connecting to a client's accounting software, bank feed, or shared storage does so behind multi-factor authentication. Single-factor password access to client systems is not permitted under our internal access policy, regardless of role or tenure.

    Evidence: policy document

    In place
  2. Least-privilege access control

    Team members are granted access only to the specific client files and systems their engagement requires, not blanket access across the client base. Access is reviewed when an engagement ends or a role changes, and removed promptly rather than left open.

    Evidence: policy document

    In place
  3. No local storage of client files

    Client accounting data is worked on inside the client's own software (QuickBooks Online, Xero, or similar) or an approved shared workspace, not downloaded and saved to an individual team member's laptop or personal device. This limits how many places a client's financial data can end up.

    Evidence: policy document

    In place
  4. Signed non-disclosure agreement for every staff member

    Every team member with any access to client financial information signs a non-disclosure agreement before their first day on an engagement, covering client data specifically, not just general company confidentiality. This is a condition of employment, not an optional add-on for larger accounts.

    Evidence: policy document

    In place
  5. Full-disk encryption on team devices

    Laptops used to access client accounting systems run full-disk encryption, so a lost or stolen device does not expose readable client data. This is a baseline device requirement before any team member is granted client system access, not a later hardening step.

    Evidence: policy document

    In place
  6. Documented onboarding and offboarding for client access

    Every engagement follows a written checklist for granting access when a team member joins a client's books and revoking it when they leave the engagement or the company. This removes the common failure mode where a departed team member's access to a client's accounting software is simply forgotten.

    Evidence: policy document

    In place
  7. Written information security program (WISP)

    A written information security program aligned to IRS Publication 4557, covering administrative, technical, and physical safeguards for taxpayer and client financial data, is being drafted ahead of handling any US tax preparation data. A summary will be published once it is adopted, and no US tax data will be processed before it is in place.

    In progress
  8. Data processing agreement templates with SCCs and IDTA

    Standard Contractual Clauses for EU client data and a UK International Data Transfer Agreement, each paired with a transfer risk assessment, are being finalized with counsel to cover the cross-border transfer of client financial data from the UK and EU. These will be signed as part of onboarding for clients in those regions.

    In progress
  9. Section 7216 consent workflow for US tax data

    A written-consent workflow meeting the format required by Revenue Procedure 2013-14 is being built so that every US client explicitly consents, before any tax return information is disclosed, to that information being used and processed by our team. No US taxpayer data will be shared ahead of a signed consent.

    In progress
  10. Errors and omissions insurance

    A professional errors and omissions policy covering the firm's advisory and preparation-support work is in the process of being placed. We will not claim coverage is in force, or name a policy, until it is confirmed bound and the certificate is on file.

    In progress
  11. Cyber liability insurance

    A cyber liability policy covering data breach response for client financial data is in the process of being placed alongside our errors and omissions coverage. As with that policy, we will not claim coverage exists until it is confirmed bound.

    In progress
  12. Third-party software vendor review

    A documented review of the security posture of every software vendor in our stack, QuickBooks Online, Xero, and connected apps, is being formalized into a standing checklist run before any new tool is adopted for client work, rather than left to individual judgment.

    In progress
  13. Written incident response plan

    A documented, tested procedure for detecting, containing, and notifying clients of a security incident involving their data is being drafted alongside the written information security program. It will define notification timelines and responsibilities before it is relied on rather than after an incident occurs.

    In progress
  14. SOC 2 Type I examination

    We intend to engage an independent auditor for a SOC 2 Type I examination once the underlying controls above (WISP, incident response, vendor review, access management) are fully in place and operating, since a Type I report only has value once there is something real for the auditor to examine. No SOC 2 report exists today, and we will not use that language about ourselves until one is issued.

    Planned
  15. ISO 27001 certification

    ISO 27001 certification is a longer-term goal, particularly for UK and Australian clients where it carries more procurement weight, and would follow after SOC 2 readiness work is complete. No certification exists today and none is implied by any control listed above until it is actually issued.

    Planned
  16. Independent penetration test

    An independent, third-party penetration test of client-facing systems and internal tooling is planned as part of SOC 2 readiness work, to validate the access and encryption controls above rather than take them on faith. No test has been performed as of today, and none is claimed.

    Planned

Questions

Questions UK clients ask about data

Does Finbryn hold a SOC 2 report?

No, not yet. A SOC 2 examination is planned, and we make no claim about SOC 2 status until a real report exists and can be shown.

Where does my Xero or QuickBooks data actually go?

Into the ledger you already own, accessed by our team under least-privilege permissions and a written device policy.

What covers the transfer of my data outside the UK?

A UK International Data Transfer Agreement (UK IDTA), signed with you before your data moves, which is how UK GDPR permits transferring personal data to a country outside the UK.

Who can I ask if my own compliance team needs more detail?

Book a call and we will walk your team through any control on this page in as much depth as your review needs.

What happens to our data if we end the engagement?

Your Xero, QuickBooks Online or Sage file remains yours throughout and after the engagement, since we never hold your data in a system you cannot access directly. Any working files we hold on our side, such as reconciliation notes, are deleted on a schedule set out in our data retention policy.

Do you use two-factor authentication and access logging on client systems?

Yes, multi-factor authentication is required for access to client accounting and banking systems, and access is logged so there is a record of who accessed what and when. Access is granted per person for the task at hand, not shared through a single generic login.

Next step

Bring your compliance questions to a call

If a control here needs more detail for your own due diligence, we would rather talk it through than leave a gap on the page.