Secure by design.
Confidential by default.

CFOLogic is committed to ensuring the confidentiality, integrity, and availability of all data under its control. This page outlines the practices and measures we take to protect the sensitive information entrusted to us and to maintain compliance with applicable regulatory frameworks.

Cloud-first, Microsoft 365

No physical servers; all data within the Microsoft ecosystem

AES-256 encryption

Sensitive data encrypted in transit and at rest

MFA enforced

On all accounts accessing our systems

Quarterly access reviews

Role-based access, revoked immediately when not needed

Request the full policy

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

What this policy covers

This policy applies to all personnel, contractors, and partners with access to CFOLogic's data systems and information. It governs all types of data - including financial records, personal information, and business records - processed or stored by CFOLogic, both electronically and physically.

We value client confidentiality and data protection above all, and are dedicated to maintaining the highest standards of information security and data privacy to protect the information entrusted to us. Our policies are built to align with industry standards and regulatory requirements.

Confidentiality, integrity, availability

The three principles every control we run is designed to uphold.

Cloud-first, Microsoft-secured

CFOLogic operates as a cloud-first firm. We do not use any physical servers within our office all data is stored within the Microsoft 365 ecosystem, handled under policies aligned with industry guidelines.

Cloud-first infrastructure

No physical servers in our office. All data is stored and processed within the Microsoft 365 ecosystem.

Microsoft compliance

We benefit from the built-in compliance controls of Microsoft 365 - access management, encryption, and retention policies aligned with industry standards.

Data handling procedures

Defined handling for data classified as sensitive, confidential, or critical, ensuring OneDrive, Teams, and SharePoint are used securely for financial data.

How we protect information

Encryption

All sensitive data, in transit and at rest, is encrypted using industry-standard encryption protocols.

Access control

Only authorised personnel may access sensitive client information, on a need-to-know basis, under a role-based access control (RBAC) system.

Continuous monitoring

Real-time monitoring tools track all data access and ensure compliance with our access controls.

Risk management

We regularly assess risks to our information systems and implement controls to mitigate them, protecting both data and systems.

Data protection

Multiple layers of controls - firewall protection, encryption, intrusion detection, and secure user authentication.

Privacy

Personal data is processed in line with applicable privacy regulations and handled with the utmost care. All staff and partners are trained on privacy and security.

The safeguards in place

Microsoft 365 integration

We use Microsoft 365 for all data storage and management. It provides a secure environment adhering to international standards including SOC 1, SOC 2, and ISO/IEC 27001 certifications.

Multi-factor authentication

All accounts accessing our systems are protected by MFA, reducing the risk of unauthorised access.

Data encryption (AES-256)

Sensitive data in transit and at rest is encrypted with AES-256, protecting it from unauthorised access and interception.

Backup & disaster recovery

Backups are performed regularly by Microsoft, and we ensure client data can be restored in the event of a disaster.

Physical security

The Microsoft data centres underpinning Microsoft 365 meet the highest physical security standards, protecting the hardware that stores data.

Periodic access reviews

Access rights are reviewed quarterly against role and responsibility. Users who no longer need access have permissions revoked immediately.

Training and incident response

Employee training & awareness

All employees undergo regular training on information security and data privacy best practices - including recognising phishing attacks, handling data securely, and reporting security incidents.Founder spreadsheets are built to show ambition. Investor and acquirer models are built to be stress-tested. When yours can’t handle the third follow-up email, your valuation starts moving - in the wrong direction.

Incident response & reporting

Detection: staff are trained to identify and immediately report potential incidents. Investigation & mitigation: a structured response plan investigates the breach and mitigates risk. Notification: if a breach affects sensitive data, clients are notified in line with legal requirements and best practices.Founder spreadsheets are built to show ambition. Investor and acquirer models are built to be stress-tested. When yours can’t handle the third follow-up email, your valuation starts moving - in the wrong direction.

Your co-pilot from chaos to confidence

CFOLogic is a strategic finance partner to growth-focused businesses, driving impact across finance strategy, financial intelligence, and financial operations. Our DNA is centred on three core values - Proactiveness, Professionalism, and Proficiency.

We help high-growth businesses navigate the complexities of company building through every stage of the journey - startup, raising capital, building business models, operationalising for scale, and achieving successful exits. Our team of finance professionals based in India delivers a full service of outsourced accounting and finance solutions to clients worldwide.

15+

Years of experience

100+

Clients served

450+

Engagements delivered

"

"Most owners don't need more reports. They need someone to look at the numbers and say do this, not that - and be on the hook for it. That's the job. Everything else is just bookkeeping with a nicer cover."

Prasad Bhalerao
Sector: B2B workflow software

Have a question about how we handle your data?

Request the full Information Security & Data Privacy Policy, or talk to us about your security review. We'll come back to you within one business day.