SECURITY & DATA HANDLING
How we handle your clients' records.
Kiaraj is a new service. This page describes how it is designed to work, and is honest about what is still being finalised. We would rather tell you that than display badges we have not earned.
HOW THE SERVICE IS BUILT
The commitments behind every engagement.
Records move by secure link
Client files are transferred through a secure, engagement-specific upload link rather than ordinary email attachments.
Access is scoped to the engagement
Work is organised into separate client and engagement folders, and access is restricted to the people working on that engagement.
Finished packs are delivered securely
Completed working papers are returned through the same secure channel, not as email attachments.
We hold no HMRC credentials
Kiaraj is not registered as anyone's agent and does not require, request or hold HMRC login details.
AI-assisted, human-reviewed
AI is used to help extract, structure and reconcile records. It may suggest; it does not silently decide. Anything ambiguous is raised as an exception rather than guessed.
We learn from the work, not from your records
Every engagement improves our process — the checks we run, the treatments we recognise, the exceptions we look for. What we retain is that generalised knowledge, not your clients' records, which are used only for the engagement they were supplied for.
Nothing sits in a general-purpose AI account
Client records are processed through controlled business accounts, not consumer AI tools or personal logins, and are never passed to unvetted integrations.
The accountant decides
Professional judgement and the submission itself remain with the accountant. Nothing we produce is filed by us.
Kiaraj prepares. Your accountant reviews and submits.
The most important control is the scope itself. Kiaraj does not file, does not act as an agent, and does not make the final professional decisions. That limits what can go wrong on our side of the line.
BEING FINALISED
What we are not claiming yet.
These are launch requirements we are working through. Until each one is documented, it will not appear on this page as a claim — and we will confirm the position in writing before any engagement begins.
- Hosting and storage provider, and the region data is held in
- Retention and deletion periods
- Enterprise commercial terms with our AI provider, prohibiting training on customer content
- The named sub-processor list, including AI providers
- AML supervision route for a preparation-only service
- Professional indemnity cover
- ICO registration
Retention, deletion, sub-processors and data-transfer terms will be documented in the engagement and data-processing documents agreed with you before records are transferred. If any of these matter to your risk assessment, ask us and we will tell you exactly where we have got to.
Questions from your risk partner?
Ask them. We will answer specifically, including where something is not finished yet.