Data & access

We don't hold your data. We work inside your systems.

There is no Accountforme platform, no portal, and no migration. Your ledgers stay in your own accounting software, and our accountants work in them as named users you create — and can switch off in seconds.

Why this matters more than a certificate. Most of the security questions in this industry exist because the provider copies your data into their own system. That is the risk being managed, and that is what a hosting certification audits. We removed the risk instead of certifying it: nothing is copied, so there is nothing of yours in our custody to lose.

We work inside your software

  • Your Xero, QuickBooks, Sage, MYOB or NetSuite subscription — not a copy, not an import
  • Named individual logins that you create, approve and can revoke in seconds
  • No shared credentials, ever — every action is attributable to a person
  • We ask for the minimum permission set the work needs, and nothing beyond it
  • Multi-factor authentication on every login

Your data stays where it is

  • No migration into a system of ours — there is nothing to migrate
  • No proprietary portal you would have to extract from later
  • No client ledgers stored on our machines or servers
  • Your bank feeds stay connected to your subscription, under your bank's controls
  • Documents stay in your Dext, Hubdoc, SharePoint or Drive

Your audit trail stays intact

  • Because we log in as named users, your software records exactly who did what
  • Nothing is posted under a generic or shared account that muddies the history
  • You can pull a full activity log at any time without asking us
  • Changes we propose but do not post are listed for your approval, not applied silently

The people who hold those logins

  • Identity, education and employment history verified before any access is granted
  • Individually signed confidentiality undertakings — per person, not just per company
  • Access reviewed periodically and removed the day someone leaves the engagement
  • A named engagement lead who is accountable for what your team does

Working practices

  • No downloading of client ledgers to local machines
  • No USB or external storage on delivery machines
  • No printing of client data — the working environment is paperless
  • Queries and files exchanged through your channels, not personal email

Leaving is one click

  • Revoke the logins and the engagement is over — technically, immediately
  • Nothing of yours is held anywhere that you need us to release
  • Every SOP and workpaper we built is transferred to you at no charge
  • Thirty days' notice, and no exit fee
Platforms

Software we hold named logins in

All third-party platforms, all on your subscription. We are not a software vendor and we have no product of our own for you to be locked into.

XeroQuickBooks OnlineSageMYOBNetSuiteDextHubdocBill.comGustoADPKarbonCCH AxcessIRISTaxCycleBrightPayClass Super

Running something not listed? We'll train on it during onboarding at our cost.

Quality control

Four eyes on everything that leaves the building

Access discipline protects the data. Review protects your reputation — and your reputation is the thing your client actually bought.

  • Every deliverable is prepared by one accountant and reviewed by another before release
  • Engagement-specific checklists built from your file standard, not a generic template
  • Monthly reporting on turnaround, error rate and query resolution time
  • Named engagement lead accountable for output — you always know who to call
  • Quarterly service review with your partner or finance lead

What we'll put in writing

  • No client data is transferred to or stored by Accountforme
  • Access is by named individual login, revocable by you at any time
  • Least-privilege permissions, agreed with you before access is granted
  • Individual confidentiality undertakings from every person on your engagement
  • No payment authorisation rights, on any engagement
  • Your completed security questionnaire, not a generic summary of ours
Ask us the hard questions
FAQ

The questions procurement asks

Do you hold ISO 27001 or a SOC 2 report?

No, and we would rather say so plainly than imply otherwise. Those certifications matter most for providers who host client data in their own platform — that is what is being audited. We do not host anything. Your ledgers live in your accounting software under your subscription, and we access them as named users you control. The risk profile is different, so the controls that matter are different: who has a login, what that login can do, and how fast you can switch it off.

So what do we tell our professional indemnity insurer?

That no client data is transferred to or stored by a third party; that access is via named individual logins within your own subscription, revocable by you at any time; that access is least-privilege and MFA-enforced; that individual confidentiality undertakings are in place; and that professional judgement and sign-off remain with your licensed staff. We will confirm all of that in writing on the engagement contract, and we will complete your security questionnaire rather than send you ours.

Where are the people doing the work located?

Our delivery teams work from our offices, not from home, on managed machines. If your policy or your client contracts require work to be performed in a specific location, tell us during scoping — we will confirm in writing whether we can meet it before you sign anything.

What about the emails and documents we send you?

Kept to what the work requires and retained on the schedule set out in your contract, then deleted. Where you would rather nothing sat in email at all, we work entirely inside your document system and shared channel — several clients do exactly that.

Can we restrict what your team can see?

Yes, and we would encourage it. Most accounting platforms have granular permission sets — read-only on some areas, no access to payroll, no bank payment rights. Give us the narrowest role that lets the work happen. We will tell you if something is genuinely blocked by it.

Do you have payment authority?

Never. We prepare payment runs and match them to invoices and approvals; you release them. We do not hold banking credentials that carry transaction rights, on any engagement, for any client.

Let's size your first engagement

A 30-minute call, a written scope, and a fixed monthly price. No obligation, no procurement process, and a two-week paid pilot before you commit to anything longer.

See pricing Book a call