1. Our security posture
CLOUDIT operates as an extension of your firm, so we hold ourselves to the same standard of confidentiality and control your clients expect from you. Security is enforced across our U.S. operations and our Global Capability Center in Gurugram, India.
2. Data protection
- Encryption: data is encrypted in transit (TLS) between you, our systems, and the platforms we work in.
- Access control: role-based, least-privilege access — team members can access only the client accounts they are assigned to, with unique credentials and multi-factor authentication.
- Your systems, your data: wherever possible we work inside your existing accounting stack (e.g., your ledger, document, and tax platforms), so your data stays in systems you control and can revoke at any time.
3. Workforce controls
- All personnel sign confidentiality and non-disclosure agreements before touching any client data.
- Background verification is performed on hiring, and staff receive recurring security and data-handling training.
- Delivery-center workstations are managed devices with restrictions on removable media and unauthorized software.
4. AI systems (Praxa & Celia)
Our AI tooling operates under the same access controls as our human team: it processes client data solely to deliver the engaged services. Client data is not used to train models for other customers, and AI outputs are reviewed by qualified accountants before anything reaches your books — no black boxes.
5. Privacy & messaging compliance
- Personal information is handled per our Privacy Policy.
- We do not sell personal information. Mobile phone numbers and SMS opt-in/consent data are never shared with or sold to third parties for marketing purposes.
- SMS programs follow carrier and CTIA guidelines: clear opt-in, STOP/HELP keyword support, and disclosure of message frequency and rates.
6. Business continuity
We maintain redundant connectivity and staffing depth at our delivery center so client deadlines — including tax-season peaks and month-end closes — are met even during local disruptions.
7. Incident response
We maintain an incident-response process covering identification, containment, remediation, and client notification. If an incident affects your data, we will notify you promptly, consistent with our agreements and applicable law.
8. Questions or reports
To report a security concern or request more detail on our controls (including for vendor due-diligence questionnaires), contact info@cloudit-us.com or +1-917-336-8923.