Trust & Control

Security, Privacy & AI

For a CPA firm the first question about AI is not what it can do, it is who stays responsible. This page describes how WorkpaperOS is actually built - where documents live, what an AI agent can reach, what gets recorded, and how you switch it off. We would rather be specific than reassuring.

Your data and AI models

We do not train on your work

WorkpaperOS trains no models of its own, so your documents and engagement data are never training material for us. Where the product calls an AI service directly - document extraction and drafting - it uses Google Document AI and Vertex AI, and model providers' API terms govern that processing. We link those terms rather than paraphrase them, because they are the providers' commitments to make, not ours.

With MCP, the account is yours

When you connect Claude, ChatGPT, or another MCP client, the AI runs under your subscription, not ours. Whatever data terms you hold with that provider are the terms that apply - including an enterprise agreement your firm has already negotiated. We are the system it connects to, not the party in the middle of your AI contract.

What an AI agent can actually reach

The same permissions as the person

You invite someone and choose exactly what they may open - which areas of the books, read-only or read-and-write, whether they can download files or run reports. Those choices are enforced on every MCP tool call, not just in the browser. An agent acting for a read-only user cannot post a journal entry, and a tool outside that user's areas is refused before it touches any data.

Refused by default

Every tool is mapped to a permission, and anything unmapped is refused rather than allowed. If we cannot establish who is asking and what they are entitled to, the call fails closed. New capability has to be granted deliberately; it never arrives switched on.

Where documents live

Private storage, row-level isolation

Files are held in private buckets - never publicly readable - and reached only through short-lived signed links. Every table in the platform database has row-level security enabled, so a session can only read rows belonging to a firm it is a member of. That isolation is enforced by the database itself, not by application code remembering to filter.

Your cloud storage stays yours

Connect OneDrive and we synchronise only the folder you choose and what sits inside it. The rest of your drive is outside our reach. Books and AttestWork anchor to separate folders, so bookkeeping files and audit evidence never land in each other's workspace.

You stay responsible

AI proposes, you post

The tools an agent can call are built to draft, not to decide. Invoices, bills, journal entries and pay runs arrive as proposals a person reviews and posts. The professional judgement stays with the professional, which is also what the independence rules expect of you.

Every tool call recorded

Each MCP call is written to an audit log with the firm, the user, the connected client, the tool, its arguments, the outcome and how long it took. Refusals are recorded too, with the permission that was missing - so you can see not only what an agent did, but what it tried.

Revoke in one click

An administrator can revoke a connected AI client from settings at any time. Revocation takes effect immediately - the connection stops working on its next call, with no waiting period and no need to contact us.

If there is a specific control your risk assessment turns on, ask us and we will tell you plainly whether it exists.