Security

The honest answer is that you should read this page and decide, not take a badge at face value.

01AccessPer-user; database-enforced
02AI processingLimited to review inputs
03RetentionDefined deletion periods
Security in practice

Clear controls, stated plainly.

Access is per-user and enforced at the database level. Financial statements and supporting information uploaded under one login are not visible to users at another firm.

AI processing uses Anthropic's Claude API. The document text and trial balance data needed to run the requested checks are sent to Anthropic, which acts as our processor under its commercial terms. Under those terms, customer inputs and outputs are not used to train models, and prompts and responses are not retained after the response is returned. Anthropic may retain content flagged by its automated safety systems, and may retain data where required by law.

Before beta access is granted, participants receive the current storage region, sub-processor list and transfer safeguards in writing, so they can assess the arrangement before uploading client data.

01

Document retention

Uploads and results are retained during participation and for 30 days afterwards. Residual backup copies are removed through the normal backup cycle within 90 days.

02

Operational records

Application and security logs are normally retained for 90 days. Support correspondence and identifiable beta feedback are retained for up to 24 months.

03

Certification status

We are not ISO 27001 or SOC 2 certified. We state the current position plainly so each participant can make an informed decision.

04

Security questionnaires

If your firm requires a security questionnaire before using a third-party tool with client data, contact info@accurao.com and we will complete it before access.