I spent five years inside Intuit's regulated financial products and two more in credit and collections before I ever touched a founder's books. Confidentiality is not a promise I make, it is the way I already work. Here is the posture, stated so your security review has something to check.
01 · NDAs
Signed before access, honored after exit
Your NDA on day one, before any credential is granted, with obligations treated as permanent rather than expiring with the engagement. No NDA on hand? I can supply a standard mutual template for your counsel to review.
02 · Credentials
Password manager, 2FA, nothing in chats
Every credential lives in a password manager, never in a document, a chat, or a spreadsheet. Two-factor authentication is on everywhere it is supported.
03 · Access
Least privilege, with an inventory
I request only the access a task needs, flag over-broad access when I find it, and keep an access inventory from day one, so offboarding is a checklist instead of an archaeology dig.
04 · Financial data
Your systems, not my copies
I ran bookkeeping, reconciliation, AP and AR, and reporting for a US company inside their QuickBooks, their drive, their bank portals. No exports to personal storage. The finance examples on this site are recreations with fictional codes and shifted figures, because the real files are not mine to show.
05 · Devices
Dedicated, encrypted, updated
A dedicated, encrypted, password-locked machine with automatic updates, in a private home office. Screen sharing on calls is window-scoped, not whole-desktop, whenever client material is open.
06 · Channels
Your Slack, your domain, your drive
Client material moves through client channels only. Nothing forwarded to personal accounts, and anything sensitive that must move gets a permissioned link, not an attachment that lives forever.
07 · Offboarding
A written handover, confirmed in writing
When an engagement ends: the access inventory handed over, ownership transferred, my access revoked, and the revocation confirmed to you in writing.
08 · The honest limit
Habits, not a certificate
I am one person, not a certified SOC 2 facility, and I will not pretend otherwise. What you get is a documented, checkable set of habits from someone who worked under KYC, AML, and GLBA guardrails and audited 63 production servers for access and risk.
Ask me any of this at the interview; the answers do not change. The short version: your NDA first, your systems only, least privilege, everything in a password manager with 2FA, and a written offboarding handover. Related: the FAQ and how we start.