How BizAxcess handles client data

BizAxcess is built for tax professionals handling other people's financial records. These are the controls in place and the disclosures you need to satisfy your own confidentiality, privacy and professional obligations.

Encryption in transit and at rest

Every request to BizAxcess and to your AI provider travels over TLS 1.2+. Your data is stored on managed Postgres with AES-256 encryption at rest and encrypted automated backups.

Secure secret storage — never in the browser

Your provider API key is sent once over TLS, encrypted server-side with AES-256-GCM using a master secret held only in the server environment, then stored as ciphertext. It is never written to browser storage, never returned to the page, and never logged — only the last four characters are shown back to you.

Tenant isolation

Every table (statements history, businesses, categorization rules, keys, billing, audit log) is protected by row-level security tied to your authenticated user ID. One firm's rows are unreachable from another firm's session, even with a valid login.

Configurable retention and deletion

You choose how long converting history is kept — from 7 days to 7 years — in Account → Privacy & retention. Older records are purged automatically, you can purge on demand, and deleting your account removes all of your data. Statement files themselves are processed in memory and never stored by BizAxcess.

Audit logs

Security-relevant events — API key added or removed, statement converted, retention changed, history purged — are written to an append-only log you can review in Account → Privacy & retention. Users cannot edit or delete entries.

Data-processing terms

BizAxcess acts as your processor for the account data it stores. Because you bring your own AI key, your firm holds the direct processor relationship with the AI provider — execute their DPA under your own account, as linked below.

AI provider disclosures

Statement content is sent from the BizAxcess server directly to the provider you choose, using your own key. BizAxcess adds no third party in between. Provider policies below are summarised from their published terms — confirm them against your engagement letters before uploading client records.

Google Gemini

gemini-3.6-flash
generativelanguage.googleapis.com (Google, US/global)
Data retention
Paid Gemini API: prompts and files are not retained beyond the time needed to serve the request (abuse logs up to 55 days). Free-tier keys are handled under consumer terms.
Model training
Paid Gemini API content is not used to train Google's models. Free-tier (unpaid) Gemini API content may be reviewed by humans and used for improvement — do not use a free-tier key for client data.
For regulated firms
Use a billing-enabled (paid) API key from a Google Cloud project covered by your firm's DPA. Free-tier keys are not appropriate for client data.

OpenAI

gpt-4.1-mini
api.openai.com (OpenAI, US)
Data retention
API inputs and outputs are retained up to 30 days for abuse monitoring, then deleted. Eligible accounts can request Zero Data Retention so nothing is stored.
Model training
API content is not used to train OpenAI models by default.
For regulated firms
Execute the DPA in your OpenAI account and request Zero Data Retention if your engagement letters or state board rules forbid third-party storage of client records.

Anthropic Claude

claude-sonnet-4-5
api.anthropic.com (Anthropic, US)
Data retention
API inputs and outputs are retained up to 30 days (shorter with zero-retention agreements), then deleted.
Model training
Commercial API content is not used to train Anthropic models.
For regulated firms
Use a commercial (paid) Console key and accept the commercial terms; consumer Claude accounts are governed by different terms.

Your responsibilities

  • Use a paid/commercial provider key — free consumer tiers may allow human review of your uploads.
  • Execute the provider's data-processing terms under your firm's own account.
  • Set a retention window in Account that matches your record-retention policy.
  • Confirm client consent or engagement-letter coverage for AI-assisted processing where required.
  • Keep BizAxcess sign-in credentials protected; anyone with your login can see your firm's data.

Read the full privacy policy

What we collect, retention and deletion choices, and which providers ever see your data.

Privacy policy

This page describes product controls; it is not legal advice.