Security
The honest answer is that you should read this page and decide, not take a badge at face value.
Access is per-user and enforced at the database level. Financial statements and supporting information uploaded under one login are not visible to users at another firm.
AI processing is limited to the information needed to run the requested review. Before beta access is granted, participants receive the current storage region, AI-processing arrangements, provider retention position, transfer safeguards and sub-processor list so they can assess the arrangement before uploading client data.
Document retention
Uploads and results are retained during participation and for 30 days afterwards. Residual backup copies are removed through the normal backup cycle within 90 days.
Operational records
Application and security logs are normally retained for 90 days. Support correspondence and identifiable beta feedback are retained for up to 24 months.
Certification status
We are not ISO 27001 or SOC 2 certified. We state the current position plainly so each participant can make an informed decision.
Security questionnaires
If your firm requires a security questionnaire before using a third-party tool with client data, contact info@accurao.com and we will complete it before access.