Why Your Books Never Touch Our Machines
Most offshore accounting works by copying your data somewhere else. Ours does not. A plain explanation of zero-local-data delivery and what it means when you fire us.
Salt works inside your cloud accounting environment over VPN-protected connections. Your financial data is never downloaded to a bookkeeper's laptop, never copied to our storage, and never leaves the systems you already control. When an engagement ends, offboarding is revoking our access — there is nothing of yours on our side to return or delete.
Zero-local-data means there is no copy of your financial data on our infrastructure. Ending the relationship is an access revocation, not a data recovery exercise.
What the alternative usually looks like
The conventional offshore model moves data to the people. Bank statements get emailed. Exports land in a shared drive. A ledger backup is restored onto a workstation in another jurisdiction so someone can work on it locally.
Every one of those steps creates a copy you no longer control, in a place you cannot audit, under a legal regime you did not choose. It usually works fine. The problem is what happens when it does not — because you cannot revoke a copy.
How the connection actually works
The mechanics are deliberately boring, which is the point.
- Named individuals get named user accounts in your accounting system — never a shared login, never your credentials.
- Access is through a VPN-protected remote session; the working environment is isolated per client.
- Local storage, clipboard transfer and printing are disabled in that session, so data cannot be moved out casually.
- Every action carries the individual's identity in your own system's audit log, not ours.
- Access is provisioned per engagement and revoked on offboarding — you can verify removal yourself, in your own admin panel.
Why the audit trail lives in your system
This is the part clients find most reassuring once it clicks. Because we work as named users inside your ledger, the record of who changed what and when is written into your accounting system's own audit log — the one you control and can export without asking us.
You are not dependent on us producing a report about our own behaviour. If your auditor wants to know who touched a journal in March, they look in your system, not in an email to us.
Because we operate as named users in your ledger, your audit trail is yours — you never have to ask us to account for our own activity.
The trade-offs, honestly
This model is slower to set up. Provisioning named access across several systems takes longer than emailing someone a backup file, and clients occasionally find the first week frustrating for that reason.
It also constrains tooling. We cannot run arbitrary local scripts over your ledger, which means some bulk operations take longer than they would if we held a copy. We think that is the correct trade, but it is a real one and worth stating rather than glossing.
Why this matters more for accounting firms
If you are a CPA or accounting practice using us as white-label capacity, your professional obligations to your clients do not transfer to us. You remain responsible for the confidentiality of their data.
Working inside your practice environment as named users means you can evidence exactly who had access to which client file, satisfy your own professional-indemnity requirements, and answer a client's 'who else sees my books?' question with something more specific than a vendor assurance.