Security & compliance

Private AI security for CPA and accounting firms.

Your AI runs in your environment, with controls your firm can inspect, document, and govern.

The data boundary

Where your data lives

For an on-premises PrivateStride deployment, approved AI workloads are processed on dedicated hardware installed in your environment.

Inside your environment

Local processing for client work

Prompts and customer content are not sent to public AI model APIs for inference. Your deployment plan documents the exact data flows, update channels, logging, backups, and support access that apply to your firm.

A governed path

01Your professional starts an approved workflow.
02The model processes the work in your environment.
03A professional reviews the draft before it is used.

Public model APIs are not part of the inference path, and your firm’s content is not used to train a shared model.

Data lifecycle

Know each copy, connection, and retention decision.

The deployment record turns the architecture into a reviewable data-flow map. Your firm approves the configuration that applies to its environment.

Inputs and outputs

Define what enters the workflow.

The record identifies approved prompts, documents, retrieved materials, generated drafts, and the systems that can receive reviewed output.

Knowledge and configuration

Separate firm material from the model.

Approved templates, policies, indexes, model files, and system configuration are inventoried so ownership and access are clear.

Logs and retention

Set the evidence period deliberately.

Query, access, administrative, and support records use the retention settings agreed for the deployment rather than an unstated default.

Updates and providers

Document every approved external dependency.

Update channels and any approved identity, monitoring, backup, or support providers are recorded with their purpose and data path.

Support access

Make remote work visible.

The support process identifies who can request access, who approves it, how it is authenticated and logged, and when it is removed.

Offboarding

Decide the exit before installation.

The signed scope assigns access removal, configuration export or deletion, record retention, and hardware-return responsibilities.

Actual settings and approved providers are documented for each deployment. Public website language does not override that record or your signed agreement.

Controls

How the system is protected

The control set is designed around the way accounting firms already manage sensitive client information.

Encryption

Protected at rest and in transit

Full-disk encryption protects stored information. TLS protects supported connections between approved users and the system.

Access

Roles, permissions, and MFA

Access is mapped to approved user groups so partners, managers, and staff can be given the permissions their work requires.

Evidence

Queries and administration logged

Query and administrative activity is logged according to the retention settings agreed for your deployment.

Boundaries

Controlled network paths

Network access is limited to the paths the deployment needs, including controlled channels for approved updates.

Support

Permissioned remote access

Remote support is enabled only under the access process agreed with your firm. Support activity is attributable and logged.

Review

People remain accountable

Outputs are drafts. Your professionals review the work and remain responsible for tax positions, advice, and client communications.

Regulatory support

Your program stays in charge

Private infrastructure can reduce unnecessary external data flows. It does not replace your firm’s legal, professional, or security responsibilities.

FTC Safeguards Rule

Documentation for your WISP

The Safeguards Rule requires covered financial institutions, including many tax preparation firms, to maintain an information security program with administrative, technical, and physical safeguards. PrivateStride provides documentation about the AI system and its controls, then works with your designated security lead so your firm can decide how to incorporate the deployment into its written information security plan.

Read the Safeguards Rule and AI guide

IRC Section 7216

Data location is one part of the analysis

Section 7216 and its regulations govern certain uses and disclosures of tax return information by tax return preparers. An on-premises architecture can reduce external data flows, but location alone does not determine compliance. Your firm remains responsible for evaluating intended uses, disclosures, consents, and contractual arrangements with its advisers.

Read the Section 7216 and AI guide

Sources: the FTC’s official Safeguards Rule guidance and the IRS Section 7216 Information Center. PrivateStride provides technical and implementation support, not legal advice or a certification of compliance.

A usable policy

The shadow AI problem, addressed at the source.

When approved tools do not fit the work, people may turn to unapproved services. PrivateStride gives your team a governed path for AI-assisted work inside your environment, with access controls and activity records your firm can manage.

The goal is simple: make the approved way useful enough that your people do not need a workaround.

Use the managing partner’s shadow AI guide

The Private AI Assessment

Find out whether your firm needs this. In writing.

Two weeks, remote, fixed fee. Where your client content is going, what your professionals already do with AI, and what a private setup would cost you each quarter. The report is yours whether or not you hire us, and the fee comes off the installation if you proceed.

$9,500Two weeksCredited toward installation
See the assessment Book a fit call 30 min · No preparation · Confidential