How We Protect Your Clients' Information

A plain-English overview for CPA firms evaluating AI For Tampa Bay. Download it to keep with your firm's written information security plan.

The AI Provider Keeps Nothing

Every workflow runs on Amazon Bedrock, Amazon Web Services' platform for running AI models.

Zero data retention

Our AWS account is set so Bedrock keeps no prompts, client details, or drafts after it responds. Nothing is written to storage by AWS or shared with the model provider.

Never used for training

What you enter is used to write your draft and nothing else. It's never used to train AI models.

No request logging

Logging of AI requests and responses is turned off, so there's no copy sitting in a log file.

Processed in the United States

AI requests are routed only to AWS data centers in the United States.

Stored Privately, Encrypted Everywhere

Your private history

Workflow inputs and drafts are saved to your firm's history so your team can find them later. Only logins on your firm's account can see them.

Encrypted at rest and in transit

Your firm's data is stored in a database hosted on AWS in the United States, encrypted at rest. Every connection uses HTTPS.

Straight to our backend

Workflow data goes directly from your browser to our backend on AWS. Our web host serves the app's pages but never receives your client data.

Nothing in our logs

We don't write prompts, client documents, or drafts to application logs. Database credentials are kept in a dedicated secrets vault, never in code.

Only Your Team Gets In

Invite-only accounts

Nobody can create a login unless they're invited. Sign-in is handled by a dedicated authentication provider.

You control your team

Your firm's owner decides who joins and can remove staff at any time.

Firms are kept separate

Every request is checked against the firm the login belongs to. Other firms can never see your data.

Limited administrative access

Only our founder has administrative access to our systems, used for setup and the support you ask for.

Your Firm Stays in Charge

You review every draft

Nothing goes to a client automatically. Your team reads, edits, and approves every draft before it's sent.

Deletion on request

If you leave, we'll delete your firm's saved history when you ask.

Security questionnaires

We're happy to complete your firm's vendor security questionnaire and provide details for your written information security plan (WISP).

Honest about where we are

We're a small, local company and haven't completed a SOC 2 audit. This page describes exactly how your data is handled so you can decide.

Questions about security? Email security@aifortampabay.com. Last updated October 2026.

Have Questions About Your Firm's Requirements?

Book a free 15-minute call. We'll walk through how your data is handled and answer anything your firm needs for its security plan.

Book a Free Call

Proudly serving St. Petersburg, Clearwater, Tampa, Bradenton, Sarasota, and all of Hillsborough, Pinellas, Pasco, Manatee, and Sarasota Counties.