Secure by design.
Confidential by default.
CFOLogic is committed to ensuring the confidentiality, integrity, and availability of all data under its control. This page outlines the practices and measures we take to protect the sensitive information entrusted to us and to maintain compliance with applicable regulatory frameworks.
Cloud-first, Microsoft 365
No physical servers; all data within the Microsoft ecosystem
AES-256 encryption
Sensitive data encrypted in transit and at rest
MFA enforced
On all accounts accessing our systems
Quarterly access reviews
Role-based access, revoked immediately when not needed
Request the full policy
What this policy covers
This policy applies to all personnel, contractors, and partners with access to CFOLogic's data systems and information. It governs all types of data - including financial records, personal information, and business records - processed or stored by CFOLogic, both electronically and physically.
We value client confidentiality and data protection above all, and are dedicated to maintaining the highest standards of information security and data privacy to protect the information entrusted to us. Our policies are built to align with industry standards and regulatory requirements.
Confidentiality, integrity, availability
The three principles every control we run is designed to uphold.
Cloud-first, Microsoft-secured
CFOLogic operates as a cloud-first firm. We do not use any physical servers within our office all data is stored within the Microsoft 365 ecosystem, handled under policies aligned with industry guidelines.
Cloud-first infrastructure
No physical servers in our office. All data is stored and processed within the Microsoft 365 ecosystem.
Microsoft compliance
We benefit from the built-in compliance controls of Microsoft 365 - access management, encryption, and retention policies aligned with industry standards.
Data handling procedures
Defined handling for data classified as sensitive, confidential, or critical, ensuring OneDrive, Teams, and SharePoint are used securely for financial data.
How we protect information
Encryption
All sensitive data, in transit and at rest, is encrypted using industry-standard encryption protocols.
Access control
Only authorised personnel may access sensitive client information, on a need-to-know basis, under a role-based access control (RBAC) system.
Continuous monitoring
Real-time monitoring tools track all data access and ensure compliance with our access controls.
Risk management
We regularly assess risks to our information systems and implement controls to mitigate them, protecting both data and systems.
Data protection
Multiple layers of controls - firewall protection, encryption, intrusion detection, and secure user authentication.
Privacy
Personal data is processed in line with applicable privacy regulations and handled with the utmost care. All staff and partners are trained on privacy and security.
The safeguards in place
Microsoft 365 integration
We use Microsoft 365 for all data storage and management. It provides a secure environment adhering to international standards including SOC 1, SOC 2, and ISO/IEC 27001 certifications.
Multi-factor authentication
All accounts accessing our systems are protected by MFA, reducing the risk of unauthorised access.
Data encryption (AES-256)
Sensitive data in transit and at rest is encrypted with AES-256, protecting it from unauthorised access and interception.
Backup & disaster recovery
Backups are performed regularly by Microsoft, and we ensure client data can be restored in the event of a disaster.
Physical security
The Microsoft data centres underpinning Microsoft 365 meet the highest physical security standards, protecting the hardware that stores data.
Periodic access reviews
Access rights are reviewed quarterly against role and responsibility. Users who no longer need access have permissions revoked immediately.
Training and incident response
Employee training & awareness
All employees undergo regular training on information security and data privacy best practices - including recognising phishing attacks, handling data securely, and reporting security incidents.Founder spreadsheets are built to show ambition. Investor and acquirer models are built to be stress-tested. When yours can’t handle the third follow-up email, your valuation starts moving - in the wrong direction.
Incident response & reporting
Detection: staff are trained to identify and immediately report potential incidents. Investigation & mitigation: a structured response plan investigates the breach and mitigates risk. Notification: if a breach affects sensitive data, clients are notified in line with legal requirements and best practices.Founder spreadsheets are built to show ambition. Investor and acquirer models are built to be stress-tested. When yours can’t handle the third follow-up email, your valuation starts moving - in the wrong direction.
Your co-pilot from chaos to confidence
CFOLogic is a strategic finance partner to growth-focused businesses, driving impact across finance strategy, financial intelligence, and financial operations. Our DNA is centred on three core values - Proactiveness, Professionalism, and Proficiency.
We help high-growth businesses navigate the complexities of company building through every stage of the journey - startup, raising capital, building business models, operationalising for scale, and achieving successful exits. Our team of finance professionals based in India delivers a full service of outsourced accounting and finance solutions to clients worldwide.
15+
Years of experience
100+
Clients served
450+
Engagements delivered
"Most owners don't need more reports. They need someone to look at the numbers and say do this, not that - and be on the hook for it. That's the job. Everything else is just bookkeeping with a nicer cover."
Have a question about how we handle your data?
Request the full Information Security & Data Privacy Policy, or talk to us about your security review. We'll come back to you within one business day.