(469) 559-6121hello@ops-automate.com

Trust & security

The controls behind every placement

When a CPA firm hands us its clients' books, "trust us" isn't an answer. These are the specific, verifiable controls that run on every OPS-Automate engagement — the same commitments written into our Privacy & Data Protection Policy.

In one paragraph

Your systems, your credentials, revocable any time. No local copies of your data — ever. Least-privilege access scoped to assigned client files. Time Doctor monitoring across the full shift. Written confidentiality that survives the engagement. Payments prepared, never released, by us. Clean, certified offboarding. Incident notification without delay.

Access

Your credentials, your kill switch

Accountants work under user accounts your firm creates — accountant-level in QBO, advisor in Xero — scoped only to assigned client files. Revoking access takes you one click and zero permission from us.

Data handling

No local copies

Data stays in your systems. No downloads, no exports to personal devices, no personal email or cloud storage. Working files, where genuinely needed, live in locations your firm designates.

Monitoring

Watched workstations

Time Doctor runs the full 9–5 shift with activity monitoring your firm can see. Work happens on managed setups, not anonymous machines.

People

Confidentiality in writing

Every accountant and success manager signs written confidentiality obligations covering your data and your clients' data — obligations that survive the end of the engagement.

Money

Segregation of duties

We prepare; you approve. Payment batches, money movement and client communication always stay with your firm. No accountant of ours has release authority.

Exit

Certified clean offboarding

Engagement ends or an accountant rotates: access is revoked, we certify no copies remain, and documented workflows — not data — transfer to any replacement.

Questions security reviewers ask

Who controls access to our systems?

Your firm does. Every accountant works under user accounts you create in your own software — accountant-level in QuickBooks Online, advisor in Xero — and you can revoke access at any moment. We never ask for owner or shared logins.

Does our data ever leave our systems?

No. Work happens inside the software your firm controls. Our accountants do not download client files, export databases, or store your records on personal devices, drives, or personal email and cloud accounts.

Can your accountants move money?

No. Segregation of duties is built into the workflow: payment batches are prepared for approval, and release always stays with your firm or your client.

What happens when an engagement ends?

You revoke access, we certify that no copies of your data remain with us, and the success manager hands over documented workflows — not data — to any replacement.

What if there's a security incident?

We notify your firm without undue delay, explain plainly what happened, and cooperate fully with your response, including any notification duties your firm has to its clients or regulators.

Do your accountants sign NDAs?

Yes. Every accountant and success manager signs a written confidentiality agreement before their first day on your files, covering your data and your clients' data — and the obligations survive the end of the engagement.

What happens to our client data if we cancel?

You revoke access — typically the same day — and we certify that no copies of your data remain with us. Our accountants work inside your tools; they do not download or retain client data, so there is nothing to hand back.

Running a vendor security questionnaire? Send it to hello@ops-automate.com — we answer them as a matter of course.

Try a dedicated junior accountant free for 7 days

No upfront payment. No contract lock-in. Your first invoice arrives after 7 days of completed work — and you only pay it if you're satisfied.