Offshore Accounting Security: SOC 2, PI Insurance and Zero Local Data
Salt holds no SOC 2 report and no ISO 27001 certificate. What that actually means, what zero-local-data does operationally, and where PI insurance sits in an offshore engagement.
Salt does not hold a SOC 2 report and does not hold ISO 27001 certification. Neither exists yet, and this page says so before a security questionnaire has to surface it, because a page about offshore data security that omits which credentials the provider lacks isn't one worth trusting. What follows is what those two credentials actually are, what zero-local-data does operationally, and where professional indemnity insurance sits when the party preparing a client's books isn't the party licensed to sign the file.
Salt holds neither SOC 2 nor ISO 27001. That's stated directly here, not left for a vendor security review to find.
What SOC 2 and ISO 27001 actually are
SOC 2 is an attestation report, not a certificate. A licensed CPA firm audits a company's controls against the AICPA's Trust Services Criteria and issues a report covering a defined system and a defined period, which then has to be renewed. ISO 27001 is different in kind: an international, certifiable standard for an information security management system, audited by an accredited certification body against a fixed set of controls.
Neither is something a company simply 'has.' Both require an external audit against a stated scope, and both lapse if not renewed. That is exactly why a specific, dated answer ('yes, SOC 2 Type II, issued by [firm], as of [date]' or 'no, not currently') is the only answer worth anything on a security questionnaire. A vague 'we take security seriously' is not that answer, from any provider.
What Salt does not hold, plainly
Salt is not SOC 2 or ISO 27001 certified, and does not describe itself as pursuing either as pending. If a certification is a hard requirement for a specific engagement, the answer belongs on the first call, not discovered three weeks into a review. What Salt can give instead is a specific, checkable written description of how access and data handling actually work, available on request.
What 'zero local data' means operationally
Not an adjective. A specific set of mechanics, summarised here and detailed in full on the security architecture piece linked below:
- Access is granted by the client, inside the client's own accounting platform, to a named individual. There is no shared login.
- Sessions run over VPN-protected, isolated remote connections; local storage, clipboard transfer and printing are disabled inside the session.
- Every action is written to the client's own audit log, under that individual's identity. The log is the client's, not Salt's.
- Nothing is downloaded, exported or synced to a Salt-controlled system as a matter of routine.
- Access is revoked by the client, inside their own platform, at the end of an engagement. It is not requested from Salt, and it does not depend on Salt confirming it first.
Zero local data means the client's own platform is the only place the data ever lives. Access is granted, logged and revoked entirely inside that system.
Why the cross-border mechanics matter specifically
Three legal requirements sit underneath any offshore engagement touching US, UK/EU or India-processed data, and a firm evaluating a provider should ask about each by name rather than accepting 'we're compliant' as an answer.
- US tax return information: IRC §7216 requires the taxpayer's specific written consent before return information is disclosed to a preparer located outside the United States. There is no exception for offshore delivery, and the statute carries criminal penalties for a knowing or reckless violation.
- UK/EU personal data: India does not hold a UK or EU adequacy decision. Transferring UK or EU personal data to an India-based team requires a recognised transfer mechanism — Standard Contractual Clauses, the UK International Data Transfer Agreement, or the UK Addendum to the EU SCCs — and a documented transfer risk assessment.
- Data processed in India: the Digital Personal Data Protection Act 2023 applies to personal data processed in India, including data handled there on behalf of an overseas client.
None of these three requirements go away because a provider says 'zero local data.' Ask specifically how the §7216 consent, the UK/EU transfer mechanism and India's DPDPA are each handled, by name.
Where PI insurance actually sits
This question deserves a direct answer, not a deflection: Salt has not published a professional indemnity or errors-and-omissions policy. That's stated here rather than left for a diligence process to uncover.
What is confirmed is where liability actually sits in a white-label engagement. Salt is not a licensed accountancy practice in any market, does not sign or lodge client work, and does not hold itself out as capable of an attest or audit engagement. The firm that reviews, signs and lodges the work is the party carrying professional liability for it. The reserved activity and the professional judgment never left the firm, so that firm's own PI insurance — not a delivery vendor's — is what's meant to cover it.
Most PI policies are written around the work the licensed firm is responsible for, not around who typed it. That varies by insurer and by policy wording, so confirm with your own broker whether delegated production work under your firm's supervision is already contemplated by your existing cover before you rely on that assumption.
Salt has not published a PI insurance policy. Liability for signed, lodged work sits with the licensed firm doing the signing. Confirm with your own broker whether your existing cover already contemplates delegated production work.
What to actually ask an offshore provider
Five questions worth asking any provider, Salt included, before signing anything:
- Ask for the SOC 2 report or ISO 27001 certificate by name, issuer and date — 'we're secure' doesn't answer a specific question.
- Ask for the §7216 consent process in writing if any US tax return information will cross the border.
- Ask what UK/EU transfer mechanism is in place, by name — SCCs, the IDTA, or the UK Addendum — if any UK or EU personal data is involved.
- Ask your own PI insurer whether delegated production work under your supervision is already within your existing policy wording.
- Ask what happens to access, not data, when the engagement ends — 'we'll delete it' matters less than 'there was never a copy to delete.'