FlowLeap

Security

Your client data stays your client data.

An AI colleague gets the same treatment as a new employee: scoped access, a clear remit, supervised work and a record of everything it did.

Human approval where it counts

Posting to a ledger, sending client communications and submitting returns require a named reviewer.

No model training on your data

Your firm's data completes your firm's work. Nothing else.

POPIA & GDPR aligned

You are the controller, we are a processor acting on your instructions.

What runs automatically, and what waits for a person

  • Reading source data

    Runs automatically inside the scopes your firm granted.

  • Preparing drafts and workings

    Runs automatically. Output is held in the review queue.

  • Writing internal drafts and filing documents

    Runs automatically where your firm enables it — filing a client statement into the right folder, for example.

  • Posting to a ledger

    Requires a named reviewer to approve.

  • Sending client communications

    Requires a named reviewer to approve. Nothing is sent unattended.

  • Submitting returns

    Requires a named reviewer to approve, always.

How the safeguards connect

  1. The permission ladder, stated accurately

    Reading source data, preparing drafts and workings, and internal filing where your firm enables it all run automatically inside the scopes you grant. Posting to a ledger, sending client communications and submitting returns always wait for a named reviewer to approve. We do not claim that nothing at all happens without approval — we claim that nothing leaves the firm, reaches a client or touches the ledger without it.

  2. Scoped access through your own systems

    Connections are made with the standard OAuth flows of the systems you already use — Xero, Sage Business Cloud, Microsoft 365, Google Workspace. You grant access from inside your own admin console, we only request the permissions a workflow needs, and you can revoke access at any time without involving us. We never ask for or store user passwords.

  3. Encryption and hosting

    Data is encrypted in transit with TLS and encrypted at rest in managed cloud infrastructure. Access to production systems is limited to named engineers, protected by multi-factor authentication and granted on a least-privilege basis.

  4. Isolation between firms

    Each firm's environment, configuration and data are kept separate. Your mapping logic, client rules and workflow configuration are not reused to serve another practice.

  5. Retention you control

    Documents and workings are retained only for as long as a workflow and its audit trail require. You tell us the retention window that fits your firm's policy, and client data can be exported or deleted on request.

  6. A full audit trail

    Every action is logged: which documents were read, what FlowLeap prepared, who reviewed it, what they changed and when it was approved. The trail is designed to be readable by a partner or a reviewer, not just an engineer.

  7. POPIA and GDPR

    We treat your firm as the data controller and FlowLeap as a processor acting on your instructions. Processing is limited to the workflows you configure, and we are happy to sign a data processing agreement covering POPIA and GDPR obligations before any live data is connected.

  8. Your data is not used to train models

    Client data is used to complete your firm's work. It is not used to train general-purpose models and it is not shared with other firms.

If your firm has a specific security questionnaire or review process, a 30-minute call is the fastest way to work through it.

Book a call