Security & Compliance
Handling another firm's client data is a position of trust. Here is exactly how we protect it.
Our operations run 100% on-site under centrally-managed controls — no work-from-home, no personal devices, no data leaving the secured environment. Below is our control framework across access, data protection, people and governance.
SOC 2
AlignedOur control environment is aligned with SOC 2 Trust Services Criteria — security, availability, confidentiality and privacy.
ISO 27001
AlignedOur information security management practices are aligned with the ISO/IEC 27001 framework.
Access & Network
- VPN-secured connections to all client servers
- Multi-factor authentication (MFA) on every system
- Role-based, least-privilege access to client data
- Multiple segregated LAN networks
- Firewall-restricted internet & blocked harmful sites
Data Protection
- Encryption in transit and at rest
- External plug-in / USB devices disabled
- Restriction on printing of client documents
- Automatic, redundant backups to prevent data loss
- Defined data retention & secure disposal policy
People & Facility
- Background checks on all personnel
- Signed confidentiality & NDA agreements
- 100% on-site operations — strictly no work-from-home
- Password-protected, centrally-managed workstations
- Licensed software only, with regular security updates
Governance & Monitoring
- Regular internal system & security audits
- Centralised device configuration & control
- Incident response & escalation procedures
- Documented policies reviewed periodically
- Client-specific security addenda on request
Need a client-specific security addendum, a completed vendor questionnaire, or an NDA in place before we begin? We routinely accommodate firm and end-client security requirements — just ask.
Focus on what's important
Ready to take the next step? Contact us today to learn how VSCPA can help your firm grow with reliable outsourced accounting.
