How we protect your data.
You’re handing over access to your books. Here’s exactly how that access is handled.
Last updated August 27, 2026
The short version
You are handing a bookkeeper access to your bank feeds and your accounting file. That is a reasonable thing to be careful about, so here is plainly how that access is handled. Everything below is drawn from a written security program we maintain internally and review at least once a year.
We ask for the least access that does the job
Where a platform offers read-only access, we take read-only. Where it offers an accountant role instead of a full admin role, we take the accountant role. You should never be asked for more access than the work requires, and if it looks like you are, say so — that is a mistake worth catching.
Multi-factor authentication, everywhere it exists
Our business email and QuickBooks Online are protected with multi-factor authentication, as is every client platform that supports it. Most real-world compromises of small firms start with a reused password and no second factor. This is the control that matters most, so it is not optional here.
Encrypted devices, unique passwords
Every device that touches client records uses full-disk encryption and locks itself after a short idle period. Credentials live in a password manager, are unique per service, and are never kept in a spreadsheet, a note, or a browser profile that syncs to a personal account. Client data is never stored on a shared or family computer.
A short list of vendors, each one checked
The fewer companies that touch your books, the smaller the exposure. Ours are QuickBooks Online, our email provider, the service that delivers this site’s contact form, and our web host — which holds no client data at all. Before any new tool is introduced, we confirm it supports multi-factor authentication, encrypts data at rest, and states in writing what it does with the data.
Access ends when the engagement does
When we stop working together, our access to your systems is removed within 30 days, and your records are returned in a standard, portable format. Retention of anything we keep afterward follows the schedule in our Privacy Policy.
If something goes wrong, you hear it from us
If client data were ever exposed, the response is to contain it immediately, work out exactly what was affected, and tell the affected clients directly — not only where a statute compels notice. Florida’s Information Protection Act sets a 30-day outer limit for notifying individuals; our intent is that you hear from Kristian well inside it, and from him personally.
What we are not
We are not a CPA firm and we do not prepare or file taxes — see our Terms of Service for the full scope. We also do not sell client information, share it for advertising, or use client financial data to train third-party artificial intelligence systems. This website loads nothing from another company’s servers, so no third party learns that you visited it.
Questions
If you want more detail before handing over access — or you represent a client with a security questionnaire — email Kristian@evergladesbookkeeping.com or call or text (352) 250-8392. A real answer from a real person, same as everything else here.