Last reviewed September 3, 2026
Confidentiality
Business and accounting information received for an authorized engagement is treated as confidential and used only for the agreed purpose, subject to legal requirements and the engagement terms. Confidentiality expectations for personnel and approved providers are established through role responsibilities and, where appropriate, written agreements.
Access and permissions
Access should follow least-access principles: named users, role-appropriate permissions, multifactor authentication where available, no shared credentials, and timely removal when access is no longer required. Clients retain responsibility for approving access and informing Black Dragon about personnel or system changes that affect authorization.
Secure document transfer
Sensitive records should be exchanged through a client-approved secure portal, managed document platform, or other agreed encrypted method. Ordinary website forms and unencrypted email attachments are not appropriate for passwords, bank credentials, tax IDs, health information, payment-card data, or confidential source documents.
US-based client coordination
Client communication and engagement coordination are managed in the United States. Any supporting resource, software provider, or cross-border processing relevant to an engagement should be disclosed and approved as part of scope and system decisions.
Quality control and review
Accounting delivery can include documented close checklists, reconciliations, supporting schedules, exception tracking, approval responsibility, and periodic scope review. The exact control and review structure depends on the engagement and is confirmed in writing.
Incident and continuity responsibilities
Suspected unauthorized access should be reported promptly through the established engagement contact. Black Dragon and the client coordinate containment, credential changes, evidence preservation, provider notification, and any legally required notices according to their respective systems and responsibilities.
Professional boundaries
Independent audits and attest services require an appropriately licensed firm. Tax and audit support is delivered or coordinated with appropriately qualified professionals based on scope and jurisdiction. This page describes operating principles, not a certification, warranty, or representation that every possible security framework applies to every engagement.
Questions
Use the contact form to request engagement-specific security information. Do not include sensitive records in the request.