Trust & security
When a CPA firm hands us its clients' books, "trust us" isn't an answer. These are the specific, verifiable controls that run on every OPS-Automate engagement — the same commitments written into our Privacy & Data Protection Policy.
Your systems, your credentials, revocable any time. No local copies of your data — ever. Least-privilege access scoped to assigned client files. Time Doctor monitoring across the full shift. Written confidentiality that survives the engagement. Payments prepared, never released, by us. Clean, certified offboarding. Incident notification without delay.
Accountants work under user accounts your firm creates — accountant-level in QBO, advisor in Xero — scoped only to assigned client files. Revoking access takes you one click and zero permission from us.
Data stays in your systems. No downloads, no exports to personal devices, no personal email or cloud storage. Working files, where genuinely needed, live in locations your firm designates.
Time Doctor runs the full 9–5 shift with activity monitoring your firm can see. Work happens on managed setups, not anonymous machines.
Every accountant and success manager signs written confidentiality obligations covering your data and your clients' data — obligations that survive the end of the engagement.
We prepare; you approve. Payment batches, money movement and client communication always stay with your firm. No accountant of ours has release authority.
Engagement ends or an accountant rotates: access is revoked, we certify no copies remain, and documented workflows — not data — transfer to any replacement.
Your firm does. Every accountant works under user accounts you create in your own software — accountant-level in QuickBooks Online, advisor in Xero — and you can revoke access at any moment. We never ask for owner or shared logins.
No. Work happens inside the software your firm controls. Our accountants do not download client files, export databases, or store your records on personal devices, drives, or personal email and cloud accounts.
No. Segregation of duties is built into the workflow: payment batches are prepared for approval, and release always stays with your firm or your client.
You revoke access, we certify that no copies of your data remain with us, and the success manager hands over documented workflows — not data — to any replacement.
We notify your firm without undue delay, explain plainly what happened, and cooperate fully with your response, including any notification duties your firm has to its clients or regulators.
Yes. Every accountant and success manager signs a written confidentiality agreement before their first day on your files, covering your data and your clients' data — and the obligations survive the end of the engagement.
You revoke access — typically the same day — and we certify that no copies of your data remain with us. Our accountants work inside your tools; they do not download or retain client data, so there is nothing to hand back.
Running a vendor security questionnaire? Send it to hello@ops-automate.com — we answer them as a matter of course.
No upfront payment. No contract lock-in. Your first invoice arrives after 7 days of completed work — and you only pay it if you're satisfied.