Your clients' data is notour training data.
It is the question every firm is asking in 2026, so it goes first: client data is never used to train models. Not ours, not as a by-product, not in aggregate.
The Agents do read your client record — that is what makes an answer about your client rather than a generic one. But that is context at the moment a question is answered, not training. Your data never becomes part of a model’s weights, and it is never pooled with another firm’s.
Built and run on Microsoft Azure
AccuMax runs on Azure and its enterprise-grade AI infrastructure — the platform our founder helped build at Microsoft, alongside SQL Server and Machine Learning Server. Microsoft’s physical, network and platform security sits underneath ours, rather than being something a new vendor had to build from scratch.
The models themselves are the ones offered within that Azure AI platform. Your clients’ data is not handed to an outside model provider, and it is not used to train anyone’s models — ours or theirs.
You do not have to take our word for the platform underneath. Microsoft publishes its own commitments on how data is handled in Azure AI: data, privacy and security for Azure AI models and the Microsoft Trust Center.
Those cover the Azure platform AccuMax runs on. They are not a certification of AccuMax itself, and we will not present them as one.
Multi-factor authentication
Required on every portal — your team's and your clients'. A stolen password on its own does not open an account.
Encrypted at rest and in motion
All content is encrypted where it is stored and everywhere it travels. That covers returns, source documents, messages and the client record itself.
Role-based access control
People see what their role gives them. A preparer, a reviewer, an admin and a client each get a different view of the same engagement.
Account and tenant isolation
Your firm's data is isolated from every other firm's, and each client account is isolated within your firm. Separation is enforced by the platform, not by convention.
Documenting us for your written information security plan?
IRS Publication 4557 asks you to account for the vendors that touch client data. Cite this page, and if your plan or your insurer needs a security questionnaire completed, ask and we will complete it.
Found something you think is a vulnerability? Write to nagesh@bfirst.ai and we will respond.
See it on your own returns
Book a 30-minute walkthrough, or start the trial and try it against a real engagement.
90-day free trial · full platform access · no credit card