Trust & security

Built by accountants who would not hand over their clients' data either

You are trusted with the most sensitive information your clients have. Any system you bring into the firm inherits that trust, so this page sets out exactly how AllDone handles client data: what the AI sees, what it never sees, where everything lives, and what gets recorded. Plain answers, because you will be asked plain questions.

What the AI sees, and what it never sees

The model helps with the judgement. It is not handed the client.

Most of AllDone is not AI at all. The mapping, the reconciliations, the computations, the schedules: automation and calculation, applying explicit rules the same way every time. The AI is invoked only where judgement is involved: suggesting wording, shortlisting options at a decision gate, helping when something is missing.

When the AI is involved, it works from a reference code, not your client's name. Client names and identifiers stay inside the application; every prompt sent to a model passes a personal-data check before it goes; and the real name is only restored when your documents are produced.

The data boundary · one prompt, traced
In the application
Meadow Joinery Limited
Reference code
C-4821
Personal-data check
passed
Sent to the model
C-4821 · DLA options
Client name in prompt
never
Prompt retention
not stored once answered
Name restored
in your documents only
Where the data lives

Yours, structurally, not just contractually

Encrypted throughout

Client data is stored on AWS infrastructure in the EU (Ireland), encrypted in transit and at rest.

Isolated between firms

Access is least-privilege, with full isolation between firms: your data is yours, structurally, not just contractually.

MFA on every sign-in

Sign-in requires multi-factor authentication, for every user, every time.

In detail: encryption at rest and in transit with TLS enforced everywhere; multi-factor authentication for every user account; row-level isolation between firms enforced in the database itself; uploads scanned for malware on the way in, with account-level threat detection; application and infrastructure audit trails retained and reviewable; and a dedicated, isolated cloud environment with its own keys and access controls, shared with nothing else.

Cyber Essentials certified
What gets recorded

Everything that matters

Every decision gate records the engine's recommendation, your partner's choice, the reason and the timestamp, to an permanent audit trail that carries into the review pack. Access to the platform is logged.

If a regulator, an insurer or a difficult client ever asks how a figure was arrived at and who decided what, the answer is on the record, not in somebody's memory.

Audit trail · specimen entries
09:41:07
Decision gate · depreciation policy · recommendation shown
09:42:31
Partner amended · reason recorded
09:44:02
Sign-in · A. Partner · MFA
Entries
permanent, carried to review pack
The model providers

No provider holds your client list

The AI in AllDone runs on Claude, from Anthropic. Their commercial API terms mean prompts are never used to train Anthropic's models and are deleted within 30 days. We hold better than that standard: Anthropic granted zero data retention on our organisation, so prompts and responses are not stored at all once the answer comes back. The exception is Anthropic's own, and we would rather you heard it from us: content flagged by their automated safety systems, or held because the law requires it, can be kept for up to two years. Combined with the reference-code design and the personal-data check, the practical position is simple: no model provider holds your client list, and no prompt identifies a client.

Your obligations, unchanged

Same standards, same sign-off, same responsibility

Nothing about your professional obligations moves. You remain the data controller for your clients' information; AllDone processes it on your instructions as your processor, under our Data Processing Agreement, with a published list of sub-processors.

The questions your clients will ask

Three answers worth having ready

"Is my data used to train AI?"

No. Our provider's commercial terms exclude training on your data, prompts are not stored once the answer comes back, and no prompt identifies a client in the first place.

"Can other firms see anything of mine?"

No. Isolation between firms is structural, enforced in the database itself, not just promised in a contract.

"Who decided the judgement calls on my accounts?"

Your accountant, every time. And it is on the record.

We built this the way we would demand it be built before uploading a single client of our own.

The full detail lives in the Data Processing Agreement, the sub-processor list and the privacy policy. For anything else, ask us the hard question.