Your financial data never leaves your environment.
We handle international financials, so trust isn't a marketing line — it's the architecture. Here's exactly how your data stays yours.
Zero local data
No client financial data is ever downloaded onto a local hard drive. We work inside your environment, full stop.
Isolated RDP & VPN
Access happens through isolated remote desktops and encrypted VPN tunnels — never raw file transfers.
Multi-jurisdictional NDAs
Ironclad, enforceable NDAs across every jurisdiction we operate in, signed before onboarding begins.
Least-privilege access
Team members get scoped access to only what an engagement requires, inside your cloud accounting platform.
Your financial data never leaves your environment.
Every engagement runs on a zero-local-data architecture. We work exclusively inside your cloud via isolated, VPN-protected connections under multi-jurisdictional NDAs. Nothing is ever downloaded to a local hard drive.
Your Cloud
QuickBooks · Xero · NetSuite
VPN Tunnel
Encrypted access
Isolated RDP
No local downloads
Salt Team
NDA-governed
What we hold, what we don't, and who can switch it off.
Written as statements you can test rather than assurances you have to take on faith. Each one applies to every engagement, in every jurisdiction we work in.
Where your data lives
In your accounting platform — QuickBooks Online, Xero, NetSuite or Zoho Books — on your subscription, under your ownership. Salt does not host a copy of your ledger, does not run a shadow database, and does not sync your records into a system of ours.
What leaves your environment
Nothing that we control. Work happens inside isolated remote sessions over VPN, and financial records are not downloaded to local drives. Where a document has to be handled — a PDF bank statement, a signed engagement letter — it stays inside your document store or the isolated session.
What we do hold
Engagement correspondence and our own working papers: the findings note, reconciliation workings, the deadline map. What we hold is listed in the engagement letter, and it is what we would hand back or delete on request at the end of an engagement, subject to any statutory retention period that applies to us as a service provider.
The off switch is yours
Because access is granted by you inside your own platform, you can revoke it in one click, at any hour, without asking us first and without waiting on a support ticket. That is a property of the architecture, not a policy we could quietly change.
Money movement
Where accounts payable is in scope we prepare, code and schedule payments inside your approval workflow — the release step stays with you. We do not ask for authority to move funds without your approval, and we do not ask for your online banking credentials.
Offboarding
At the end of an engagement you revoke access yourself, and we confirm in writing what we held, what has been returned, and what has been deleted. No exit fee is charged for handing your own records back.
A named person, scoped permissions, your audit log.
The detail that matters most is the least glamorous one: we ask for individual logins, never a shared account. That is what makes the trail in your own platform mean something.
- 01
Access is granted by you, inside your platform, to a named individual with their own login. There is no shared Salt account, so every action in your ledger is attributable to a person in your own audit log.
- 02
Permissions are scoped to the engagement. A bookkeeper working your reconciliations does not receive payroll or banking permissions because they are convenient to grant.
- 03
Every individual assigned to your engagement is covered by the NDA before the access request is made — not after.
- 04
When someone rolls off your engagement, we tell you, and their access is removed. When an engagement ends, access is revoked at your end and confirmed at ours in writing.
- 05
Work is performed through isolated remote desktops over encrypted VPN tunnels. Financial records are not copied to local machines, personal devices or consumer file-sharing accounts.
Which vendors can reach anything.
We have not published a subprocessor table yet, and we would rather say that plainly than post an approximate one. A subprocessor list is checked line by line in a security review, so it is only worth anything if it is complete and current.
What we can tell you today without qualification: your ledger stays in your own platform on your own subscription, we do not host a copy of it, and no vendor of ours is inserted between you and your accounting software. Ask us and we will send a written list of every vendor with any access to client data, along with what each one can reach.
Request the vendor listThe things we could say and won't.
Anyone can list what they have. The useful disclosure is what they don't — so here it is, before you have to ask.
We are not ISO 27001 or SOC 2 certified
We operate to the practices described on this page, and we are not going to describe a certification we do not hold or imply one is imminent. If a certification is a hard requirement for your engagement, say so on the first call and we will tell you where we actually are.
Salt is not a registered tax or BAS agent
Where a jurisdiction requires a registered agent to lodge a filing, we tell you in writing who lodges and under whose registration before you sign. An individual's registration is theirs, not the firm's, and we will not present it otherwise.
We publish no client names without permission
No logos, no testimonials, no review scores, no star ratings. Every case study on this site is anonymised unless that client gave written permission to be named — which is the same protection you get.
Send your security questionnaire to hello@saltaccountinggroup.com and you will get a written answer to every question, including the ones where the answer is no.
“Every engagement is governed by multi-jurisdictional, enforceable NDAs and a zero-local-data storage architecture. No client financial data is ever downloaded onto local hard drives.”
Salt security commitmentSecurity questions
Talk to us about your data-security requirements.
Tell us where you trade and what shape the books are in. You get scope, price and a start date in writing within one business day — no obligation.