Your financial data is the product. We treat it that way.

911-CFO is a finance firm first. We hold client data to the standard our own work demands, and we tell you plainly what is in place today and what is still being built.

Five layers of protection surrounding your financial data, from multi-factor sign-in to the audit log
Each layer has to hold on its own. Together they surround your data.

The controls

Our security program is designed around the requirements of the FTC Safeguards Rule (16 CFR Part 314).

Multi-factor sign-in for everyone

Every user signs in with Microsoft Entra ID and a second factor. There are no shared accounts.

Encryption in transit and at rest

Data is encrypted between your browser and our service, and on disk. Appliance disks are fully encrypted.

Separate workspaces

Each firm's data is isolated at storage, query and AI-search level. Isolation will be tested by an independent penetration test before the multi-firm platform opens.

Consent before tax data

The assistant will not use tax return information unless the taxpayer's written consent is on file, as IRC section 7216 requires.

Never used for training

Your records answer your questions and nothing else. In the cloud, Microsoft states that prompts and answers are not used to train its models (Microsoft Foundry data privacy).

A log of every action

Sign-ins, data access and exports are written to an audit log that firm administrators cannot alter.

Tested on a schedule

An annual penetration test and a vulnerability scan every six months, as the Safeguards Rule sets out.

A plan for the worst day

A written incident response plan, with notice to affected people and regulators as federal and North Carolina law require.

How we manage AI risk

We follow the NIST AI Risk Management Framework and its generative AI profile to govern, map, measure and manage the risks of the assistant.

  • Answers must cite a source from your own documents.
  • No source means no answer.
  • Safety checks screen questions and answers for personal data and misuse.
  • A 911-CFO advisor reviews any figure before it goes into advice.

Questions from your IT or compliance team

We are glad to walk your team through our controls in detail, including the architecture of the private AI appliance. Email contact@911cfo.com with the subject line "Security review".

See it with your own numbers

We are opening 911CFO.ai to a small group of firms first. Tell us how you run your budget and forecast today, and we will show you what changes.