Security is how we operate, not a badge we point at
When you outsource accounting, you give a third party standing access to your bank feeds, payroll registers, customer lists and vendor banking details. That access is the whole job. It is also the whole risk. Our internal controls are built around that fact.
The program follows the control principles any serious security review tests: least privilege, named user accountability, strong authentication, encryption in transit and at rest, segregation of duties, and a written record of who did what. We hold no security certification or third party audit report, and we will not imply one. What follows is a plain description of how the work actually runs.
Every engagement is covered by a signed services agreement and a mutual confidentiality agreement before a single credential is issued. If you need extra terms, such as a data processing addendum or a restriction on where the work is performed, we put that in writing during onboarding rather than after the first close.
The controls we operate under
Six practices that apply to every client account, from a single location restaurant group to a multi-state services firm.
Least privilege access
Staff get the narrowest access that lets them do the job. A bookkeeper posting and reconciling in QuickBooks Online does not hold payroll admin in Gusto or ADP. A payroll specialist does not hold bill payment rights in Bill.com. Access is granted per engagement and per system.
Named accounts, no shared logins
Every person who touches your file has an individual named account. No generic service accounts, no passwords passed around a team, no logging in as the owner. When an entry shows up in your audit trail, a specific person is attached to it.
Multi-factor authentication everywhere
MFA is required on every system used to reach client data: accounting platforms, payroll portals, banking portals, email, remote access and our document portal. Authenticator apps or hardware keys wherever the platform supports them, text message codes only when a platform offers nothing stronger.
Encrypted transfer and storage
Files move over TLS encrypted connections and sit encrypted at rest in the platforms we use. Payroll registers, W-2 and 1099-NEC data, bank statements and check images never travel as plain email attachments.
A document portal instead of an inbox
Source documents go through a client portal with per-user permissions and an upload log. You can see what was uploaded, by whom, and when. Open document requests run through the same portal, so nothing critical lives only in one person's mailbox.
Learn moreVetted staff under signed confidentiality terms
Staff assigned to client work are background checked before they start and sign a confidentiality and data handling agreement covering client records, personally identifiable information and payroll data. Those obligations survive the end of employment.
Who gets access to what
A sample of how we scope permissions by role. Your exact grants are written down at onboarding and confirmed with you before anyone logs in.
| Role on your account | Typical access granted | Deliberately not granted |
|---|---|---|
| Bookkeeper | QuickBooks Online, QuickBooks Desktop or Xero at a level that posts and reconciles, plus read-only bank and credit card feeds | Payroll administration, vendor banking changes, release of outgoing payments |
| AP specialist | Bill.com, Ramp or Expensify as a submitter or approver at the level you set, plus W-9 collection and read-only access to vendor records | Final payment release, direct bank login credentials, payroll files |
| Payroll specialist | Gusto, ADP or Paychex at the processing level, plus the W-4 and pay data needed to run cycles and file Forms 941 and 940 | General ledger admin rights, AP payment release, banking portals |
| Controller or review lead | Review level access across NetSuite, Sage Intacct or your general ledger, plus the close checklist and reporting | Standing payment release rights on your bank accounts |
| Account manager | Document portal, scheduling and communication tools only | Accounting, payroll and banking systems unless separately assigned in writing |
Scroll the table sideways on a small screen.
Payment, monitoring and workspace controls
These apply to the parts of the work where money moves and where a mistake is expensive.
- Segregation of duties in the payment cycleThe person who enters a vendor bill is not the person who approves it, and neither one releases the funds. We staff AP so entry, approval and release sit with different people, with your team holding at least one of those roles.
- Dual approval on outgoing paymentsWe configure Bill.com, Ramp or your bank's own approval rules so any payment above a threshold you set requires two approvals. We do not ask for release rights we do not need to do the work.
- Vendor bank changes verified out of bandA request to change a vendor's bank account or remit-to address is verified by phone to a number already on file, never by replying to the email that made the request. Each change is logged with the date and the confirming contact.
- Audit logging left on and keptPlatform audit trails stay enabled. We also keep our own record of access grants, credential issuance and permission changes for each client, and we produce it on request.
- Quarterly access reviewsOnce a quarter we list every person holding access to your systems and confirm each one still needs it at that level. Anything unused is removed rather than left open.
- Clean desk and locked screensClient documents are not printed unless a filing requires it, printed material is shredded the same day, screens lock when unattended, and client data stays off personal devices.
- Managed devices onlyMachines used for client work run full disk encryption, current patching, endpoint protection and automatic screen lock, with remote wipe available. Removable media and unapproved file sharing tools are blocked.
From first login to same-day revocation
Every credential we hold moves through the same four stages.
-
Scoped before anything is posted
Ahead of the first transaction we document which systems we need, which permission level in each, and which named people get them. Wherever the platform allows it, you provision us as users inside your own subscriptions, so the master account stays yours.
-
Issued to individuals, with MFA
Each person sets up their own credential and enrolls in MFA. We do not accept a shared login. If a platform genuinely supports only one admin seat, we tell you before onboarding and agree a compensating control with you in writing.
-
Reviewed on a set cadence
Access is reviewed quarterly, and again immediately whenever the staffing on your account changes. Any new grant is documented the same way the original one was, and you are told about it.
-
Revoked the same business day
When someone rolls off your engagement or leaves the firm, access is removed the same business day across every system on their list, their portal account is disabled, and client material is cleared from their device. We confirm the revocation to you in writing.
Retention, deletion and a clean exit
Your records should be easy to get back and easy to have removed. Both are written into the engagement before work starts.
- The file stays in your nameThe books, the source documents and the working papers belong to you. We work inside your subscriptions wherever we can, so the accounting file, the payroll account and the bill pay account remain yours while we operate them.
- Retention agreed in writingRetention periods are set in your engagement letter by record type, including the employment tax records behind Forms 941, 940, W-2 and 1099-NEC. We do not hold client data past the agreed period without asking you first.
- Deletion on requestYou can ask us to delete the copies we hold at any time, apart from records we are required to keep for tax or legal reasons. We confirm in writing what was deleted, from which systems, and on what date.
- A complete handover if you leaveMoving the work in-house or to another firm gets you a full package: trial balance, general ledger detail, bank and credit card reconciliations, payroll registers, filed returns, fixed asset and depreciation schedules, and open AP and AR at the transition date.
- Straight talk on incidentsIf we identify unauthorized access involving your data, we contain and revoke first, notify you promptly with what we know at that point, and follow up with a written account of what happened and what changed as a result.
Security questions we get asked
Do you hold a security certification or audit report?
No, and we will not imply otherwise. We hold no security certification, attestation or third party audit report. Our controls are built on the principles those reviews test: least privilege, named user accountability, MFA, encryption, segregation of duties and logging. If your procurement process requires a formal report from a service provider, raise it early and we will tell you plainly whether we can meet it.
Will you sign our NDA or vendor security addendum?
Yes. We sign a mutual confidentiality agreement with every client before credentials are issued, and we will review your own NDA, data processing addendum or vendor terms. If a clause commits us to something we do not actually do, we say so and propose language that matches reality instead of signing and hoping.
Who exactly will have access to my books?
A named list, agreed with you at onboarding and kept current. You get the names, the roles, the systems and the permission level for each person, plus written notice whenever that list changes.
Can you work with healthcare practices and card payments?
Yes, and we scope the engagement to limit exposure. Reconciling a merchant deposit does not require full card numbers, and posting a patient payment does not require clinical records. We hold no healthcare or payment card attestation of any kind. If your practice needs us to sign a business associate agreement, we review the scope and terms before work starts.
Where is the work performed?
We tell you during onboarding which team supports your account and where they work from, and it goes in the engagement letter. If your own policy restricts where client data may be accessed from, tell us before onboarding and you will get a straight answer on whether we can meet it.
Can we audit access ourselves?
Yes. Because we work inside your subscriptions wherever the platform allows it, you can pull the user list and the audit log yourself in QuickBooks Online, Xero, NetSuite, Sage Intacct, Bill.com, Gusto or ADP at any time without asking us. We also produce our internal access record for your engagement on request.
Ask the hard security questions before you hand over the books
Book a free consultation and we will walk through access levels, payment approvals and document handling for your exact systems, then send a no-cost quote for the work. Call (209) 456-5966 or email info@yfgconsultants.com.