SECURITY & NON-DISCLOSURE (NDA) POLICY

Effective Date: August 10, 2026

Firm Name: Virtual Accountants & Consultants (“Firm”, “We”)

1. Global Security Commitment

Securing client financial records, bank logins, tax returns, and proprietary business metrics is our highest operational priority. We enforce strict technical, administrative, and physical security measures across all global client engagements—from initial diagnostic evaluations to ongoing monthly accounting.

2. Mutual Non-Disclosure Framework (NDA)

Before receiving access to any client accounting software, bank feeds, tax portals, or financial records, Virtual Accountants & Consultants executes a legally binding Mutual Non-Disclosure Agreement (NDA) signed by authorized representatives of both parties.

Standard NDA Provisions (Incorporated by Reference):

  • Definition of Confidential Information: Encompasses all non-public financial ledgers, tax records, bank account numbers, commission structures, client/broker lists, login credentials, and business models.
  • Mutual Protection Obligation: Both the Firm and the Client agree to hold all shared confidential data in strict confidence and shall not disclose, copy, publish, or release it to any unauthorized third party without prior written consent, except as required by law.
  • Permitted Operational Use: Confidential data is accessed strictly for evaluating, building, and delivering agreed accounting, tax compliance, and CFO advisory services.
  • Term of Protection: Confidentiality obligations remain legally binding during active service delivery and endure for a period of two (2) years following the formal termination of the business relationship.

3. Technical Data Infrastructure Safeguards

  • Read-Only Bank Access: We enforce a read-only accountant feed policy for bank and credit card accounts whenever supported. We never request direct withdrawal or administrative control over client banking funds, except when executing authorized Accounts Payable via secure platforms (Bill.com, Wise).
  • Tokenized Gateway Security: Client credit card numbers and direct debit bank accounts provided for monthly retainers are tokenized directly through PCI-DSS Level 1 compliant processors (Wise, Rizon, Worldpay, Stripe). Our firm never directly handles, views, or stores 16-digit credit card numbers or CVV codes.
  • Vaulted Credential Storage: All client software credentials (QuickBooks Online, Xero, Wave, tax portals) are encrypted and managed using enterprise password vaults featuring mandatory Multi-Factor Authentication (MFA) and dynamic access revoking.

4. Global Delivery Center & Team Security Controls

To deliver high-margin, enterprise-level virtual support, our core operational delivery team is located in Pakistan. We enforce uniform security standards across borders:

  1. Individual Personnel NDAs: Every accountant, financial modeler, and analyst employed by Virtual Accountants & Consultants signs an individual, legally binding employee NDA and data privacy agreement before receiving access to client files.
  2. Role-Based Access Controls: Team members are granted strictly minimum-necessary access permissions corresponding to their assigned client accounts.
  3. Clean-Desk & Restricted Hardware Rules: Work is executed across secure, encrypted network connections. Local downloading, personal device transfer, or unauthorized external storage of client financial data is strictly prohibited.
  4. Immediate Access Revocation: Offboarding protocols automatically revoke all system permissions and password vault access immediately upon a team member’s reassignment or departure.

5. Incident Response & Breach Notification

Virtual Accountants & Consultants maintains an incident response protocol. In the event of a confirmed or suspected data breach affecting client financial records, our technical team will notify impacted clients via email within 48 hours of confirmation, outlining the nature of the breach, the scope of affected records, and the immediate corrective actions implemented.