Security & Data Handling
This page is for the people who ask "what happens to my data, and who can reach it" before a contract is signed — typically an IT or data lead evaluating FirmMetrics™ or WorkSight Metrics™ on behalf of their firm. It describes posture and outcome, not implementation detail.
FirmMetrics™ and WorkSight Metrics™ have different data postures
FirmMetrics does not import your firm’s data. Its dashboards are built using Power BI’s own connectivity directly against your CCH Practice or Practice CS data — there is no bulk copy of your firm data into an AccountingTek BI database to drive the reporting. The one exception: the AI-generated summary feature holds a rolling 30-day aggregate of your KPI figures, which is replaced each time it runs rather than accumulated. That aggregate is time-bounded and self-expiring by design.
WorkSight Metrics does take custody of data. Your firm supplies CCH Workflow data through our authenticated customer portal, and it is held in a US-hosted Azure SQL database for as long as your account is active.
Where your data lives
AccountingTek BI is 100% US-based. All Azure infrastructure runs in US regions, and all Power BI content is hosted in US-based workspaces. Nothing is processed or stored outside the United States.
Access control
Access to WorkSight Metrics data is role-gated: upload and read endpoints reject any request from an account without the required portal role. Within that, your firm’s data is scoped server-side to your authenticated identity — it is resolved from who you are, not from a parameter in the request, so one firm cannot reach another firm’s data by changing an input. Uploaded files are validated for type and size before anything is stored.
Multi-factor authentication is enforced on every portal account, backed by Microsoft Entra ID with Authenticator. This is not optional or opt-in.
One fact we think is important to state plainly rather than let a reviewer discover it: a small number of AccountingTek BI administrators hold a role that can reach customer data, for support and account administration. Every vendor in this category is in the same position — we are not aware of one that isn’t — and we would rather say so directly than have it read as an omission.
AI features: KPI summaries and Atlas chat
Two distinct AI-powered features exist, and they carry different data exposure:
- AI-generated KPI summaries are built from prompts our system composes in code, from your own account’s figures. There is no free-text input on this path — you don’t type anything into it, and neither does anyone else.
- Atlas, our in-portal assistant, accepts free text that you type. Your questions, and Atlas’s tool-scoped responses, are logged.
Both paths send content to Azure OpenAI, hosted in a US region. By default, Azure OpenAI retains prompts and completions for up to 30 days for abuse monitoring, with the possibility of human review of flagged content — that default applies to both paths, since it governs prompt content rather than who authored it. We are working to reduce that retention window; this page will be updated to reflect the change once it takes effect.
AI-generated summaries are visible to your own users in the portal, and are also visible to AccountingTek BI administrators, who review them for quality and tuning. Atlas conversations are logged and reviewable by administrators for the same reason. Both are a deliberate part of how we operate and improve the product, not incidental access.
Backups
Database backups use Azure SQL’s standard point-in-time recovery, and our Azure SQL databases run with zone redundancy enabled. When data is removed from active systems, it stops being reachable immediately; backups containing it age out over Azure SQL’s standard recovery window rather than being deleted the same instant, which is normal for any backup system and worth being precise about rather than saying "permanently deleted."
Systems we connect to, and services we use
These are not the same thing, and a lot of security pages blur them. A source system is something your firm owns, hosts, and controls, that we connect to and read from directly, with your authorization. A subprocessor is a third party we engage to process your data on our behalf.
| Systems we connect to and read from (yours) | Services we use to process your data (ours) |
|---|---|
| CCH Practice / Practice CS | Microsoft Azure (SQL Database, Blob Storage, Functions) Microsoft Power BI Microsoft Entra ID / Microsoft Graph Azure OpenAI |
Your firm hosts and secures the system in the left column — that responsibility is yours, not ours. The right column is the complete list of third parties that touch your firm’s data on our behalf.
WorkSight Metrics works differently, and isn’t a system we connect to at all: your firm exports data from CCH Workflow and submits it through our authenticated portal. We never connect to your CCH Workflow environment directly — the export you provide is the extent of our access, and only happens when you submit one.
What we don’t claim
We are not SOC 2 or ISO 27001 certified — we won’t claim either. We’re a small team, and we’d rather earn trust with specific, checkable statements than with adjectives like "enterprise-grade" or "bank-level" security, which this page’s reader has learned to discount on sight.
Questions before you sign
If your firm needs a signed data processing agreement, or has security questions that go beyond this page before you’re ready to move forward, contact us and we’ll work through your requirements directly.
This page describes what our product touches. For how we handle data from website visitors — form submissions, cookies, and analytics — see our Privacy Policy instead; that is a separate, broader question from what this page addresses.
