How client financial data is handled
Bookkeeping, payroll, and tax work requires access to sensitive financial data. This page describes the access model, what is and isn't stored, and how access is removed at the end of an engagement.
Client-controlled access
Access to accounting, payroll, or filing systems is granted by the client or firm directly, using each platform's own user-permission controls (accountant or staff-level access, not full account ownership) wherever the platform supports it. Access is never requested beyond what's needed to complete the agreed scope of work.
What's stored, and what isn't
Working files are limited to what's needed to reconcile books or prepare a filing for a given cycle. RazaPro does not request or store full banking credentials, and does not retain client financial data beyond what's needed to support the current or immediately prior filing period.
Offboarding
At the end of an engagement, or at any point on request, access granted to RazaPro is revoked by the client through their own platform's permission settings, and any local working copies of client data are deleted.
Communication
Sensitive documents and credentials are shared only through the client's or firm's preferred secure channel, not sent as plain email attachments where a more secure option is available.
Security controls in place
These controls cover every device and account that RazaPro uses for client work.
| Control | What it means in practice |
|---|---|
| Multi-factor authentication | Turned on for email, accounting software, cloud storage and every other account that touches client data. |
| Password manager | Unique, generated passwords for every account. Passwords are never shared in email or chat. |
| Full-disk encryption and screen lock | Work devices are encrypted and lock automatically after a few minutes idle. |
| Written information security plan | A written plan following the IRS template in Publication 5708, covering access, devices, data retention and incident response. Available to client firms on request. |
| Mutual NDA | Signed before any client data is shared. |
| Incident notice | Your firm is told within 72 hours of RazaPro discovering any incident that affects your clients' data, with what happened and what was done. |
| Least access | A named, limited user in your own software. No shared logins and no stored banking credentials. |
| Deletion | Local working copies deleted at the end of an engagement, and on request at any time. |
To report a security concern, email hello@razapro.com (also listed in security.txt).
What RazaPro does and does not claim
RazaPro is a team of specialists based in Pakistan, working for US firms and businesses. It does not hold a SOC 2 report or an ISO 27001 certificate, and does not claim to. Instead, firms get the controls in writing:
- A mutual NDA before any client data is shared, and a confidentiality agreement from anyone who works with that data.
- A copy of the written information security plan on request.
- Written answers to your security questionnaire, so your firm can document service-provider oversight in its own written information security program, as the FTC Safeguards Rule expects.
- Access you control: a named user in your own software, no shared logins, no stored banking credentials, removed by you at any time.
- Deletion at the end: local working copies are deleted when the engagement ends, and on request at any time.
If your firm uses a third-party provider, the AICPA Code asks you to tell clients and to protect confidentiality through an agreement or client consent. See offshore bookkeeping for US CPA firmsfor the rules, and how client financial data should be handled.