Security
How We Protect Your Financial Data
Our security posture in plan language
Your financial records are among the most sensitive documents in your life. Bank statements, tax returns, forecasts, and payroll data tell the story of your business and your livelihood. We don’t take lightly the trust involved in handling them. This page describes how BSFG approaches data security — not as a compliance checkbox, but as a core part of what it means to be a principled financial partner.
WHAT WE DO FAQ
-
We disable AI features in our document environment.
AI tools built into platforms like Google Workspace can process your documents automatically and without your knowledge. We keep these features disabled and verify that configuration quarterly, because these platforms have a documented pattern of re-enabling AI features through product updates.
-
We don’t record our meetings.
No AI note-taking tool joins our calls. Your financial conversations stay between us.
-
When we use AI, we protect your data.
BSFG uses AI tools for analysis and efficiency — and we do it under commercial data agreements that prohibit the platform from training on your information. Client financial data is handled in a dedicated, integration-free environment. We do not upload Social Security numbers, account numbers, or tax identification numbers to any AI tool, ever.
-
We audit our tools every quarter.
Every app connected to our systems is reviewed. Any connection we can’t identify and justify is revoked immediately. We document these audits.
-
We use strong credentials and two-factor authentication.
Every BSFG account uses a unique, generated password stored in a dedicated password manager. Multi-factor authentication is required across all platforms that touch client data. We also actively encourage our clients to maintain their own secure credential management systems and written data handling policies — because BSFG's security practices protect only the slice of your data we touch. The rest of your organization's security posture is yours to govern, and we're glad to help you think through where to start
-
We maintain active threat detection on all devices.
All devices used for client work run active security software. Any confirmed breach triggers immediate notification to affected clients.
WHAT WE ASK OF YOU FAQ
-
No. Please don’t email us financial documents.
Email isn’t a safe channel for sensitive files. Documents sent as attachments are stored permanently on servers neither of us controls, and email accounts are the most common entry point for financial fraud. Instead, please use the secure shared folder we set up for you. It’s access-controlled and only visible to you and BSFG. When in doubt, send us a link — not the file itself. Not sure how? Just ask. We’re glad to walk you through it.
-
Please implement a business-wide security and data handling policy internally.
BSFG maintains thoughtful data-hygiene systems with routine audits and documentation logs- but we only touch a portion of your organization’s data. Your full credential surface, internal systems, and staff practices are yours to govern. AI-driven cybercrime is becoming more sophisticated faster than most businesses are adapting. Old ways of managing data are no longer sufficient. This is the lowest effort, highest- impact thing you can do your business right now—not next quarter, this one. We’re happy to help you think through where to start. We stay current on business data management best practices and we’re glad to be a thinking partner on this.
YOUR RIGHTS
You can request at any time that your data not be used in AI-assisted workflows. You can ask what tools are processing your information. If BSFG ever experiences a security incident affecting your data, you will be notified promptly and transparently. We publish this statement because we think you deserve to know how your data is handled — and because we’re willing to be held to it.