Security & confidentiality
A posture you can check, in plain language
Trust accounting means handling some of the most sensitive records a firm holds. This page states the practice's security posture plainly. Every item on it is a current operating fact. Anything that changes comes off this page, not into a footnote.
The short version: Sum Certain records and reports. We do not hold, move, or approve the movement of money, ever. Bank access is read-only: we can view statements and transactions, and nothing else. Access to your accounting file is scoped to the work and protected the way we would want our own firm's records protected.
We also practice what we ask: our own contact form asks for no trust-account details, and we will never ask for client-identifying information before an engagement letter is in place.
- We never touch client funds
- Sum Certain works from official bank statements and read-only bank access. We record and report; we cannot move money, initiate transfers, or disburse from any account.
- Least-privilege access
- Access is scoped to what the work requires: read-only bank access, your accounting file, and the documents you share. It is reviewed when an engagement begins and ends.
- Multi-factor authentication everywhere
- Every tool in the practice's stack is protected with MFA. No shared logins, no exceptions.
- US-hosted tooling
- The practice's core systems (accounting, document exchange, and email) are hosted with US-based providers under US data terms.
- Encrypted document exchange
- Statements and supporting documents move through an encrypted client portal, never as email attachments.
- Confidentiality in writing
- Every engagement letter includes a confidentiality commitment covering your firm's and your clients' information.
For your vendor file
The Vendor Diligence Packet
Your firm has an obligation to vet the providers who touch client information. This is the document that answers it: a short packet organized around ABA Formal Opinions 477R, 483, 498, and 512, covering fund custody, confidentiality, remote supervision, our AI policy, incident notification, subprocessors, insurance, and records on exit.
No form, no email required. Download it, read it, put it in the file. Version 1.1, reviewed quarterly.
Who else touches the work
Subprocessors, named
A subprocessor is any third party that stores or processes data in the course of our work. This is the full list. It is disclosed in every engagement letter, reviewed quarterly, and updated here first whenever a tool is added or removed. None of them can move client money.
| Service | What it does | Client data it touches |
|---|---|---|
| Intuit QuickBooks Online | Core accounting platform and system of record | Client financial records |
| LeanLaw | Trust and IOLTA workflows inside the client's QuickBooks file | Client trust and matter data |
| Clio or CosmoLex | Read-only access to the firm's practice-management data, only where the firm already uses them | Client trust and matter data |
| Financial Cents | Practice workflow, client tasks, and the reconciliation sign-off log | Client names and task status |
| Dext and Uncat | Receipt capture and uncategorized-transaction queries | Client transaction data |
| Anchor | Proposals, engagement-letter e-signature, billing, and the encrypted client portal for document exchange | Engagement documents, billing contact, and the statements and supporting documents your firm shares. Never client funds. |
| Anthropic | AI-assisted drafting and flagging items for review, under a signed data processing agreement with zero data retention. It never computes or approves a reconciliation. | Limited client data under commercial terms, never used to train any model |
| Google Workspace | Practice email and document storage | Client documents and correspondence |
| Mercury | The practice's own business banking, which receives your payment for our services | None. No access to client trust funds, books, or matter records. |
| Netlify, Formspree, and Calendly | Website hosting, contact-form delivery, and call scheduling | None. The forms request no client information. |
In writing
Questions we expect
Ask us the hard questions
Security questions belong in the open. Bring yours to a readiness call, or send them by email if you prefer it in writing.