Gaapio Logo - AI-Powered Technical Accounting Platform

Security and Trust

Gaapio has completed a SOC 2 Type 2 examination, and every model provider it routes to operates under a contractual zero-data-retention agreement — meaning what you upload is not retained by them and is not used to train their models. Attestations, controls and subprocessors are published in our trust center.

Data privacy is the first question we get asked, ahead of price and ahead of features. That is the correct instinct: you are considering putting pre-release financial information into a tool that uses AI. This page answers the question directly, and the trust center below has the artifacts.

Looking for attestations, controls, subprocessors or a copy of the SOC 2 report? Our full trust center is at security.gaapio.com — including the controls list, subprocessors and documentation.

The short version

SOC 2 Type 2

An attestation examination under AICPA standards — independently tested controls over security and availability, examined across a period rather than at a point in time. Report available under NDA via the trust center. (SOC 2 is an examination, not a certification; we say so because you'd notice.)

Zero data retention

A contractual zero-data-retention agreement with every model provider we route to — currently Anthropic, OpenAI and Google. Your content is not retained by them and is not used to train their models.

Licensed authoritative sources

The FASB Codification, licensed directly from the Financial Accounting Foundation. The guidance is licensed, not scraped.

Not a settings toggle

These are contractual commitments, not preferences you have to remember to configure.

Why zero data retention is the question that matters

Most AI data-privacy discussion focuses on whether a vendor trains on your data. That matters, but it is only half the question. The other half is what happens at the model layer — the provider actually running the inference.

A tool can have an excellent privacy policy of its own and still pass your content to a model provider that retains it for thirty days, or uses it to improve their service, or both. The commitment has to extend all the way down the chain, and it has to be contractual rather than configurable.

That is why we run zero-data-retention agreements with each provider we route to rather than relying on default API terms. It also means the answer does not change when someone on your team or ours adjusts a setting.

Multi-model routing, and why it does not weaken this

Gaapio routes across multiple model providers — currently Anthropic, OpenAI and Google — rather than depending on one. That is a resilience and quality decision — different models are better at different parts of the work, and single-provider dependency is a risk.

The obvious concern is that more providers means more places your data goes. Which is why the zero-data-retention requirement is a condition of routing to a provider at all, not something negotiated per relationship. Every provider in the chain operates under the same commitment. The current list is published in the subprocessors section of the trust center.

For firms: independence and self-review

Public accounting firms ask a different security question, and it is not really about data. It is about independence: whether using the same tool on both sides of an engagement creates a self-review threat.

Part of the answer is architectural: a firm and its client work in separate organizations, with documents held in a per-company store and access scoped by role — so Gaapio is not acting as both preparer and reviewer inside one shared workspace. That mitigates the threat but does not by itself resolve it — the analysis also depends on what firm personnel do with the output. That is worth confirming with your own independence group, and we are happy to join that conversation — see solutions for audit firms.

Need something specific? Security questionnaires, the SOC 2 report under NDA, a DPA, or a conversation with someone technical — get in touch and we will route it properly rather than sending you a PDF.

Frequently asked questions

It depends on where the tool sends your data and what happens to it there. The questions that matter are whether the vendor holds a current SOC 2 Type 2 report, whether zero data retention is contractual with every model provider in the chain, and whether those commitments are contractual rather than configurable. Gaapio has completed a SOC 2 Type 2 examination and holds a zero-data-retention agreement with every model provider it routes to.

Still have questions?

Security questions are best answered by a person. Talk to us, or start with the trust center at security.gaapio.com.

Trust center: Attestations, controls, subprocessors and documentation: security.gaapio.com. This page summarizes; the trust center is authoritative.