Your numbers stay yours
Outsourcing your finance function means trusting a partner with sensitive data. We treat that trust as the foundation of the relationship.
Confidentiality & NDAs
Every engagement starts with a signed NDA covering our full team.
Secure cloud infrastructure
Client data is hosted and processed on secure, access-controlled cloud platforms.
Access controls
Role-based access ensures only the people who need your data can see it.
Encrypted file sharing
Documents move between us over encrypted channels, not email attachments.
Regular backups
Scheduled backups protect your records against accidental loss.
Business continuity
Documented procedures and team redundancy mean no single point of failure.
Data protection practices
Policies aligned to recognized data-protection best practices.
Independent oversight
Quality reviews and audit trails on every deliverable that leaves our team.
Full Security & Confidentiality Policy
At YAxis Advisory Ltd. ("YAxis Advisory", "YAxis", "we", "us or "our"), security and confidentiality are fundamental to the way we provide outsourced accounting, finance, FP&A, payroll, workforce and business-process services.
Our clients may entrust us with sensitive financial, commercial, operational, employee and personal information.
We therefore seek to maintain appropriate technical, organisational and operational safeguards designed to protect the confidentiality, integrity and availability of information entrusted to us.
This Security & Confidentiality Policy describes our general approach.
Specific security requirements may also be established under a client agreement, NDA, Data Processing Agreement, Statement of Work or other written contract.
1. Our Security Approach
Our security programme is based on the following principles:
- confidentiality by default;
- least-privilege access;
- controlled access to client information;
- secure technology platforms;
- secure document handling;
- appropriate authentication;
- encryption where supported;
- data protection;
- business continuity;
- incident response;
- confidentiality obligations;
- appropriate personnel practices; and
- continuous improvement.
We seek to maintain security practices appropriate to the nature, volume and sensitivity of the information we process.
2. No Certification Claim
YAxis Advisory currently does not represent that it holds ISO 27001 certification, SOC 2 Type II attestation or any other information-security certification unless expressly stated and supported by current certification documentation.
We do not use references to such certifications to imply that YAxis has obtained certification where it has not.
Where appropriate, we seek to align our practices with recognised information-security, privacy and data-protection principles and applicable contractual requirements.
Our security programme will continue to develop as our business, technology environment and client requirements evolve.
3. Scope
This Policy applies to information handled in connection with our services, including:
- accounting;
- bookkeeping;
- financial reporting;
- FP&A;
- financial modelling;
- budgeting;
- forecasting;
- cash-flow analysis;
- payroll;
- HR administration;
- workforce services;
- BPO;
- advisory;
- management reporting; and
- other professional services.
It applies to information handled by authorised employees, contractors and service providers to the extent relevant to their responsibilities.
4. Confidentiality by Default
We treat non-public client information as confidential.
Confidential information may include:
- financial statements;
- accounting records;
- bank information;
- transaction records;
- payroll information;
- employee records;
- customer records;
- supplier records;
- tax information;
- financial models;
- forecasts;
- budgets;
- business plans;
- contracts;
- investor information;
- pricing information;
- strategic plans;
- operational information;
- credentials and access information where legitimately required;
- personal information; and
- other non-public information.
Confidential information may be disclosed only where:
- authorised by the client;
- necessary to provide an agreed service;
- required by applicable law;
- required by a competent authority;
- necessary to protect legal rights; or
- otherwise permitted under the applicable agreement.
5. Non-Disclosure Agreements
Confidentiality obligations apply to YAxis client engagements.
Where appropriate, YAxis may enter into a separate Non-Disclosure Agreement ("NDA") with a client.
An NDA may establish additional obligations regarding:
- confidential information;
- permitted use;
- disclosure;
- security;
- return or destruction;
- duration of confidentiality; and
- remedies for unauthorised disclosure.
Where an NDA exists, its terms will apply to the relevant engagement.
6. Access Control
We seek to ensure that access to client information is limited to authorised individuals who require access to perform their responsibilities.
Our access-control approach may include:
- role-based access;
- least-privilege principles;
- individual user accounts;
- restricted administrative privileges;
- access based on job responsibilities;
- access reviews;
- removal of unnecessary permissions;
- access modification following role changes; and
- prompt removal of access when personnel leave.
Technical access does not by itself authorise a person to use information for purposes outside their responsibilities.
7. User Authentication
We use reasonable authentication controls appropriate to the systems we operate.
These may include:
- strong passwords;
- multi-factor authentication where supported;
- individual user accounts;
- controlled administrative access;
- authentication monitoring;
- account recovery procedures; and
- access revocation.
Personnel are expected to protect credentials and must not knowingly disclose passwords or authentication information to unauthorised individuals.
8. Multi-Factor Authentication
Where supported by the relevant technology platform, YAxis encourages or requires multi-factor authentication for accounts with access to sensitive information.
The availability and configuration of MFA may vary depending on:
- the platform;
- client systems;
- subscription level;
- technical limitations; and
- client configuration.
9. Cloud Infrastructure
We use cloud-based technology platforms appropriate to our operations.
These may include:
- Google Workspace;
- accounting platforms;
- financial reporting systems;
- cloud storage;
- document-management platforms;
- communication platforms;
- video-conferencing systems;
- workflow systems; and
- other business applications.
We seek to select reputable providers that maintain appropriate security controls for the services they provide.
The security of third-party infrastructure is also governed by the respective provider's policies, terms and security controls.
10. Google Workspace
YAxis uses Google Workspace for business email, collaboration and related business functions.
Depending on configuration, Google Workspace may be used for:
- email;
- document storage;
- spreadsheets;
- shared files;
- calendars;
- meetings;
- collaboration;
- administrative functions; and
- business communication.
Access is controlled through authorised accounts and appropriate permissions.
Where available and appropriate, security controls such as multi-factor authentication and administrative access controls are used.
11. Secure File Sharing
Where practical, sensitive information should be transferred through controlled cloud-storage or secure collaboration platforms.
This may include:
- Google Drive;
- approved client portals;
- secure file-sharing platforms;
- controlled document repositories; and
- other approved systems.
We encourage clients to avoid transmitting highly sensitive information through ordinary unsecured channels where a more secure alternative is available.
12. Encryption
We use systems and communication platforms that provide encryption or other security protections appropriate to the service and information involved.
Where supported by the relevant platform, information may be encrypted:
- during transmission; and/or
- while stored.
The exact encryption features available may depend on the relevant third-party technology provider and configuration.
13. Client System Access
Clients may provide YAxis with access to:
- accounting software;
- ERP systems;
- payroll systems;
- HR systems;
- banking platforms;
- cloud storage;
- financial reporting systems; and
- other business systems.
Where YAxis accesses client systems:
- access should be limited to the agreed scope;
- appropriate permissions should be used;
- individual accounts should be used where practical;
- access should be removed when no longer required; and
- personnel should use the access only for authorised purposes.
Where possible, clients should avoid sharing administrator credentials when individual user access can be provided.
14. Segregation of Client Information
We take reasonable steps to prevent unauthorised access to information belonging to different clients.
Where shared technology platforms are used:
- client-specific folders or workspaces may be established;
- permissions are configured based on need;
- access is restricted according to role; and
- client information is not intentionally disclosed to another client.
15. Personnel Confidentiality
Personnel and authorised contributors who have access to client information are expected to maintain confidentiality.
They must:
- use information only for authorised purposes;
- protect client information;
- protect system credentials;
- avoid unauthorised disclosure;
- follow applicable security procedures;
- report suspected security incidents; and
- return or securely dispose of information when required.
Confidentiality obligations may continue after an individual's employment or engagement with YAxis ends.
16. Security Awareness
We seek to maintain security awareness among relevant personnel.
Awareness may include:
- phishing awareness;
- password security;
- multi-factor authentication;
- safe document handling;
- data protection;
- secure communication;
- social-engineering awareness;
- access-control requirements; and
- incident reporting.
17. Quality Control
Depending on the nature of an engagement, financial and operational deliverables may be subject to review.
Quality-control measures may include:
- preparer/reviewer segregation;
- reconciliation;
- analytical review;
- approval workflows;
- checklists;
- documented procedures;
- version control;
- management review; and
- appropriate audit trails.
The level of review depends on:
- the scope of the engagement;
- materiality;
- risk;
- client requirements; and
- the nature of the deliverable.
18. Audit Trails
Where supported by the relevant system, we may maintain audit trails or activity records.
These may include:
- login information;
- user activity;
- document activity;
- workflow approvals;
- changes to records;
- access logs; and
- system events.
Such records may be used for:
- security monitoring;
- quality control;
- troubleshooting;
- compliance;
- investigation;
- dispute resolution; and
- operational management.
19. Backups
Where appropriate, we use scheduled or platform-provided backups to reduce the risk of accidental data loss.
Backup arrangements may vary depending on the system and service provider.
Backups are intended to support recovery but cannot eliminate all risks of data loss.
20. Business Continuity
We seek to maintain operational continuity through appropriate organisational practices.
Depending on the engagement, these may include:
- documented procedures;
- standard operating procedures;
- shared knowledge;
- controlled documentation;
- backup personnel;
- cross-training;
- workflow documentation;
- secure access to necessary information; and
- structured handover procedures.
The objective is to reduce dependence on a single individual and support continued service delivery during operational disruptions.
21. Security Incident Management
A security incident may include:
- unauthorised access;
- unauthorised disclosure;
- accidental disclosure;
- lost or stolen information;
- compromised credentials;
- malware;
- phishing;
- inappropriate access;
- system compromise;
- data loss; or
- another event that may affect confidentiality, integrity or availability.
Where we become aware of a suspected security incident, we will take reasonable steps to:
- identify the incident;
- contain the incident;
- assess the potential impact;
- investigate the circumstances;
- mitigate potential harm;
- restore affected systems where appropriate; and
- implement corrective measures.
22. Client Notification
Where a security incident affects client information, YAxis will assess whether notification is required under:
- applicable law;
- the client agreement;
- the Data Processing Agreement;
- the NDA; or
- other applicable contractual obligations.
Where notification is required, we will provide information reasonably available to us regarding the nature of the incident and relevant mitigation measures.
23. Data Protection
Security practices are implemented alongside our Privacy Policy and applicable data-protection requirements.
Where YAxis acts as a processor/service provider:
- the client determines the purposes of processing;
- YAxis follows documented instructions;
- access is restricted;
- appropriate security measures are applied; and
- additional data-processing requirements may be established contractually.
Where required, YAxis may enter into a Data Processing Agreement with the client.
24. Subcontractors and Service Providers
We may use third-party service providers to support our operations.
These may include:
- cloud providers;
- accounting software providers;
- communication platforms;
- document-storage providers;
- payment providers;
- payroll platforms;
- technology providers; and
- other service providers.
Where third parties have access to confidential or personal information, we seek to establish appropriate contractual, confidentiality and security requirements.
Where a client agreement requires prior approval for subcontractors or sub-processors, we will follow the agreed process.
25. International Data Processing
YAxis is based in Bangladesh and provides services to clients internationally.
Information may therefore be accessed or processed from Bangladesh or other locations authorised for service delivery.
Where applicable laws impose restrictions on international data transfers, we seek to address such requirements through:
- appropriate contractual arrangements;
- Data Processing Agreements;
- applicable transfer mechanisms;
- appropriate service-provider controls; and
- other lawful safeguards.
26. Data Retention and Disposal
Information is retained according to:
- client agreements;
- engagement requirements;
- legal obligations;
- regulatory requirements;
- accounting requirements;
- business requirements; and
- legitimate requirements to establish, exercise or defend legal claims.
When information is no longer required, we seek to:
- delete it;
- securely destroy it;
- anonymise it; or
- otherwise dispose of it appropriately,
subject to applicable legal or contractual retention obligations.
27. Physical Security
Where YAxis handles physical documents or devices containing confidential information, we seek to apply reasonable physical-security measures.
These may include:
- controlled access;
- secure storage;
- restricted document access;
- appropriate disposal;
- secure handling of devices; and
- protection against unauthorised physical access.
28. Device Security
Personnel using devices to access client information are expected to maintain reasonable security measures.
Depending on the device and environment, this may include:
- password or biometric protection;
- device locking;
- operating-system updates;
- security updates;
- malware protection where appropriate;
- secure network connections; and
- appropriate storage and disposal procedures.
29. Remote Work
Where personnel work remotely, they are expected to maintain appropriate confidentiality and security.
This may include:
- avoiding unauthorised persons viewing confidential information;
- using secure internet connections;
- protecting devices;
- locking screens;
- avoiding unnecessary local storage of sensitive information;
- using approved systems; and
- following YAxis security procedures.
30. Client Security Responsibilities
Security is a shared responsibility.
Clients should:
- use appropriate authentication;
- enable MFA where available;
- maintain secure credentials;
- provide appropriate user permissions;
- promptly remove unnecessary access;
- notify YAxis of suspected compromised credentials;
- use secure file-sharing mechanisms;
- maintain security over their own systems;
- provide accurate information; and
- follow agreed information-sharing procedures.
YAxis cannot be responsible for security failures originating solely from systems, credentials or infrastructure controlled by the client.
31. Security Reviews and Continuous Improvement
Our security practices may be reviewed periodically.
Reviews may consider:
- changes in technology;
- client requirements;
- emerging threats;
- changes in applicable law;
- incidents;
- operational experience;
- changes in service providers; and
- business growth.
Where appropriate, we may introduce additional controls to improve our security posture.
32. Security Standards and Certifications
YAxis Advisory currently does not represent that it holds:
- ISO 27001 certification;
- SOC 2 Type I or Type II attestation;
- PCI DSS certification;
- or another information-security certification,
unless expressly stated and supported by current certification documentation.
We seek to develop our security programme in accordance with recognised security and privacy principles appropriate to our business and client requirements.
We may pursue formal certifications or attestations in the future as our business develops.
33. No Absolute Security Guarantee
We implement reasonable technical, organisational and operational safeguards.
However, no:
- website;
- cloud platform;
- information system;
- internet connection;
- electronic communication method; or
- storage system
can be guaranteed to be completely secure.
Accordingly, YAxis does not represent that information will be immune from every possible security threat.
Our commitment is to maintain appropriate safeguards and respond responsibly to identified security incidents.
34. Updates to This Policy
We may update this Security & Confidentiality Policy from time to time to reflect:
- changes in our business;
- changes in technology;
- changes in security practices;
- changes in applicable law;
- changes in service providers;
- new security risks; or
- improvements to our controls.
The latest version will be published on our website.
35. Contact
For security, confidentiality or privacy enquiries:
YAxis Advisory Ltd.
H-108 (Flat-301), Road-10/2, Block-D, Niketon, Gulshan, Dhaka-1212, Bangladesh
Privacy & Security: privacy@yaxisadvisory.com
General Enquiries: info@yaxisadvisory.com
For suspected security incidents involving YAxis, please use:
Subject: URGENT — SECURITY INCIDENT
Please provide as much relevant information as possible, including:
- your name;
- organisation;
- contact information;
- description of the suspected incident;
- relevant systems or information involved;
- date/time of the incident, if known; and
- any immediate action already taken.
We will assess the report and take appropriate action based on the nature and severity of the matter.
© 2026 YAxis Advisory Ltd. All rights reserved.