26 & Co. / Trust

Security & Privacy

Careful handling of financial information. Clear expectations. Human-reviewed analysis.

Overview

26 & Co. handles sensitive financial and business information as part of our fractional CFO services and tax return analysis. We are building administrative, technical and organizational safeguards designed to protect client information and limit access to authorized personnel and approved service providers.

Access controls

Access to client information is limited based on job responsibilities and business need. Team members are expected to use individual accounts, appropriate authentication controls and least-privilege access. Sensitive financial documents should not automatically be accessible to sales or marketing personnel unless specifically required and authorized.

Document and financial data handling

We may process tax returns, accounting reports, QuickBooks data, bank statements, financial statements, accounts receivable and payable information, and other records necessary to provide the requested CFO services. Client information should be used only for legitimate business purposes related to the requested services. Please submit only information necessary for your engagement.

Accounting system access

Where practical, we prefer view-only or read-only access when performing financial analysis. Standard fractional CFO analysis does not require payment authority, banking authority or the ability to move client funds.

Automation and AI

We may use approved software, automation and AI-assisted tools to organize, extract, analyze and summarize financial information. Approved providers should be subject to internal security and privacy review. Client information should not be knowingly submitted through unauthorized personal AI accounts. Material financial recommendations and reports remain subject to human review before delivery.

Vendors and service providers

Third-party providers may support document storage, accounting integrations, communications, payments, hosting, analytics and automated processing. Our program is designed to review providers and their access to client information. Contact us about the providers and submission methods applicable to your engagement.

Payment security

Our intended payment workflow uses third-party payment processors. Do not send full payment-card details through contact forms or document submissions. Online checkout availability will be confirmed by our team.

Data retention

Client information should be retained only as reasonably necessary to provide services, meet contractual obligations, support legitimate business needs and satisfy applicable legal or regulatory requirements. Information should be securely deleted or destroyed when retention is no longer necessary, subject to applicable requirements.

Incident response

We are developing documented procedures intended to identify, investigate, contain and respond to security incidents involving client information. Any required notifications will be handled according to applicable requirements.

Security program

We are developing a formal information-security program covering access control, multi-factor authentication, vendor oversight, risk assessment, data handling, security training, incident response, business continuity, data retention, audit and evidence tracking, and AI and automated-processing governance.

SOC 2 readiness

26 & Co. is building its security and operational controls with SOC 2 readiness in mind. SOC 2 is an independent reporting framework used to evaluate controls related to areas such as security, availability, confidentiality, processing integrity and privacy. We do not represent 26 & Co. as having completed a SOC 2 examination. Such a claim requires a completed independent examination.

An evolving approach

Security practices may evolve as our company, technology and regulatory environment change. This page describes our approach and development priorities; it does not promise absolute security or independently verified certification. 26 & Co. does not provide legal, tax, cybersecurity or regulatory compliance advice.

Privacy Policy

Information you provide through an inquiry or engagement is used to respond to your request and provide the requested CFO or financial-analysis service. This may include business contact details and the financial records described above. Approved service providers may process information on our behalf, including through approved software and automated tools.

Access, processing and retention follow the approach described on this page. Submit only information you are authorized to provide and that is relevant to your requested service. Contact our team to ask about access, correction, retention or deletion, or about the providers applicable to your engagement. Requests remain subject to applicable legal and contractual requirements.

This notice may evolve with our services and technology. Please contact us before sending sensitive information if you need clarification.

Client Terms

Your engagement agreement defines the agreed services, fees, responsibilities and delivery terms. Website information describes our services and does not replace that agreement. Confirm your scope and approved submission method with our team before providing sensitive records.

Our offering is fractional CFO analysis and decision support, including historical tax return analysis and succession readiness. Historical analysis does not replace current operating records, a forecast or a formal appraisal. We work alongside your bookkeeper, CPA and other advisers; we do not provide legal or tax advice, tax preparation, audits, reviews or compiled financial statements.

Financial analysis depends on timely, complete information and human review. Recommendations do not guarantee profits, financing or a transaction outcome.

Questions about your information?

Talk with our team before submitting sensitive records.

Talk With 26 & Co.