Security & data handling
Secure systems, limited access, and no sensitive data by email.
We use secure systems for files and access, limit access by role, document important work, and review client-facing output before delivery. The rule is simple: passwords, tax documents, bank details, Social Security numbers, and other sensitive information do not belong in ordinary email.

The short version
Four habits protect the work before technical detail begins.
Use the secure channel
Files and credentials follow the approved process. Convenience is not a reason to move sensitive data into email.
Limit access
Access follows the person’s role and the work they need to perform, not broad visibility by default.
Document the work
Requests, open items, preparation, review, and delivery follow a visible process instead of informal handoffs.
Keep a human accountable
Automation and AI may assist internal work. A person reviews client-facing output before it leaves the firm.
Role-based access
The right person gets the access required for the work—no more.
Access is a working responsibility, not a permanent convenience. The engagement process should make who can see or change information clear enough to review.
- Access follows assigned responsibility.
- Credentials use the secure sharing process.
- Open access questions are documented and escalated.
- Client-facing work retains a named reviewer.


The data path
Sensitive information should have a clear route.
The secure process starts before the file arrives and continues through review and delivery. It is not a single portal link added after the fact.
- Request: the client receives a specific request and approved channel.
- Collect: files or access are provided through secure systems.
- Use: assigned team members perform the scoped work.
- Review: important output is checked before delivery.
- Deliver: the final package follows the approved client process.
Human review
Security also means knowing who is accountable for the output.
Named ownership
The engagement and important work do not disappear into an anonymous queue. Responsibilities and open questions remain visible.
Maker-checker review
One person prepares recurring work and another person checks it before the client-facing package is released.
Clear escalation
If a request, access issue, or data-handling question falls outside the normal process, the team pauses and escalates instead of improvising.
AI and automation may help with internal drafting, categorization, pattern review, or workflow support. They do not remove the requirement for accountable human review before client-facing work leaves the firm.
Shared responsibility
The process works when both teams follow it.
Slate and Summit
- Provide the approved file and access process.
- Limit access by role and scope.
- Review important work before delivery.
- Redirect sensitive email and document exceptions.
- Provide current detailed security information when appropriate.
The client team
- Use the approved secure channels.
- Protect credentials and avoid shared informal access.
- Respond to access changes and open questions promptly.
- Tell us when a user, system, or responsibility changes.
- Escalate anything that does not look right.
Security details can change with systems, vendors, and the engagement. Current documentation should be reviewed before relying on any vendor-specific, certification, encryption, data-residency, or incident-response statement.
Frequently asked
Direct answers about security and access.
Can I email tax documents or bank information?
No. Use the secure system provided for the engagement. If sensitive information arrives by email, the team redirects it to the approved process instead of treating the exception as normal.
How are passwords shared?
Through the approved secure credential-sharing process, not ordinary email, chat, or a shared document. The exact instructions are provided during onboarding.
Does everyone on the team see all client information?
Access is controlled by role and the work assigned. The goal is to give people the access required for their responsibility without making broad access the default.
Do you use AI?
Yes, carefully. AI may support internal drafting, categorization, pattern review, or workflow. A person reviews client-facing work before it leaves the firm.
Can you provide detailed security documentation?
Detailed, current information can be provided when appropriate. Specific claims about vendors, certifications, encryption, data residency, or incident response should be confirmed against the documentation in effect at that time.
Ask directly
Understand how your files, access, and reports will move before the work starts.
We will explain the secure onboarding process, the roles involved, and where current technical documentation is the right next step.