Security
Your client data stays your client data.
An AI colleague gets the same treatment as a new employee: scoped access, a clear remit, supervised work and a record of everything it did.
How the safeguards connect
The permission ladder, stated accurately
Reading source data, preparing drafts and workings, and internal filing where your firm enables it all run automatically inside the scopes you grant. Posting to a ledger, sending client communications and submitting returns always wait for a named reviewer to approve. We do not claim that nothing at all happens without approval — we claim that nothing leaves the firm, reaches a client or touches the ledger without it.
Scoped access through your own systems
Connections are made with the standard OAuth flows of the systems you already use — Xero, Sage Business Cloud, Microsoft 365, Google Workspace. You grant access from inside your own admin console, we only request the permissions a workflow needs, and you can revoke access at any time without involving us. We never ask for or store user passwords.
Encryption and hosting
Data is encrypted in transit with TLS and encrypted at rest in managed cloud infrastructure. Access to production systems is limited to named engineers, protected by multi-factor authentication and granted on a least-privilege basis.
Isolation between firms
Each firm's environment, configuration and data are kept separate. Your mapping logic, client rules and workflow configuration are not reused to serve another practice.
Retention you control
Documents and workings are retained only for as long as a workflow and its audit trail require. You tell us the retention window that fits your firm's policy, and client data can be exported or deleted on request.
A full audit trail
Every action is logged: which documents were read, what FlowLeap prepared, who reviewed it, what they changed and when it was approved. The trail is designed to be readable by a partner or a reviewer, not just an engineer.
POPIA and GDPR
We treat your firm as the data controller and FlowLeap as a processor acting on your instructions. Processing is limited to the workflows you configure, and we are happy to sign a data processing agreement covering POPIA and GDPR obligations before any live data is connected.
Your data is not used to train models
Client data is used to complete your firm's work. It is not used to train general-purpose models and it is not shared with other firms.
If your firm has a specific security questionnaire or review process, a 30-minute call is the fastest way to work through it.
Book a call