Security by separation and control

Confidential client work starts only after firm onboarding.

I operate Compliant so that public enquiries and client work remain separate. This website is for information and firm-level conversations only; case material is accepted through the agreed secure route after onboarding.

Security and confidentiality approach

01

Public website

Marketing pages and business-enquiry forms only. Do not submit client names, case facts, account details or documents.

02

Controlled adviser environment

Client work is kept separate from the public website and accepted only through the approved Microsoft environment after firm onboarding.

03

Firm-level due diligence

Evidence about access, sharing, data protection and continuity is provided through the adviser firm’s due-diligence and onboarding process.

Protection principles

Client data is accepted only after safeguards are confirmed.

  • Named user access with multi-factor authentication
  • Permissions limited to the agreed work and relevant firm area
  • Authenticated sharing with no public or anonymous case links
  • Access removal when the engagement or business need ends
  • Documented logging, review, incident and continuity arrangements
  • Retention and secure deletion terms agreed during onboarding

Named access, never shared credentials

Where work requires access to a firm system, access remains attributable and controlled by that firm. Only the permissions needed for the agreed work should be granted, with multi-factor authentication wherever supported. Compliant will not ask anyone to disclose a password or authentication code.

Data-protection roles

The intended model is that the adviser firm acts as controller for end-client data and Compliant acts as processor for the contracted paraplanning work. The position is confirmed in the engagement and data-processing terms. Compliant may separately act as controller for its own legal, security, accounting and administration records.

The adviser firm remains responsible for its lawful basis, transparency obligations, data minimisation and complete regulatory client file.

Due-diligence information

Prospective firms can request the information relevant to their outsourcing review. Detailed configuration, evidence, retention arrangements and procedures are handled through due diligence rather than published on the open website.

Start with the firm, not the client case.

Talk to Steven about your requirements. Do not send client data through the website or ordinary business-enquiry route.