Trust

Security and governance

Client files are processed on local hardware your practice controls. Your firm's rules decide what runs, the Ledger records what the AI did, and a named partner rules before anything leaves. This page sets out each control, gives its status and links to the full security documents.

A partner signs a sheet of Cast & Rule letterhead with a fountain pen beside a Cast & Rule desk card and a brass lamp.

Questions partners ask

Can our staff send client data to a cloud AI through Cast & Rule?

Cast & Rule sends work to a cloud model only when your firm's rules allow it for that task and that person, after names and tax references are swapped for placeholders on your own machine. Tools outside Cast & Rule, such as a browser on a staff laptop, stay under your own policy and IT settings, and our AI-use policy template helps with those.

Can we prove nothing left the building?

Yes. For any period, the no-cloud report lists every AI run, where it ran and what left the machine through Cast & Rule, and you check it without asking us. With cloud AI switched off, it shows no cloud calls at all.

Who controls what the AI is told to do?

Your firm decides what may run and for whom. The tasks themselves are built, signed and versioned by us, so neither your staff nor anyone else can quietly change what the AI is told to do; your practice adjusts only the settings we allow, and each change is recorded. We found no competitor offering tasks that are maintained centrally and extended for each firm (as of September 2026).

What happens when an AI model changes or is withdrawn?

Nothing changes without you. Each task is tested against named model versions, and a new version installs only after you've tried it on your own machine and approved it. If a cloud model is withdrawn, the task carries on with the tested model on your hardware. We found no competitor offering upgrades that you test on your own machine and that install only when you approve them (as of September 2026).

Could one client's information turn up in another client's work?

No. Each client's records sit in their own encrypted store, with their own key, and each piece of work reads from one client only. Delete a client's key, including its backed-up copies, and their store can no longer be read.

Can we tell what the AI did from what our people did?

Yes. The Ledger marks every change as made by a person or by the AI, with the task, its version, the model and the documents it changed. Each entry is locked to the one before it, so a later change shows up.

Where the work lives

From the ground up: where the work lives, and what guards it at each layer.

Every piece waits at Awaiting partner until a named partner rules.

  1. On the practice's machineClient files are processed on local hardware the practice controls. Each client's records sit in their own encrypted Strongroom store.
  2. Cloud only if you allow itA cloud model runs only for tasks and people your rules allow, after names and tax references are replaced with placeholders on your machine. It's off by default.
  3. Rules decide what may runThe firm's AI-use policy decides which tasks may run and on which sources, with controls on every connection.
  4. What the AI did is recordedThe Ledger records what the AI did, including the agent's connections. Other apps on the machine are outside its coverage.
  5. Released only on a rulingAny action that sends, files, posts, pays or deletes in an outside system needs a partner's approval of that exact action.

Install and cloud options

Client documents, prompts and answers stay on a machine in your practice's office. There are two ways to run it, and this is where the differences are set out.

Managed by us

Our service looks after updates, the task catalogue and health checks, and never receives client content. It sees the operational details of each run: who ran what, when, and its status. Results your rules allow off the machine are encrypted before they leave.

Fully local

The whole system runs on your machine and keeps working if your internet goes down.

Outside the machine in either case

Two flows sit outside the machine whichever you choose: Xero, read through its own official connector, and remote support, where we reach your machine to help. Each is set out, with where the data goes, before it's used.

The security documents

The detail behind this page, with the status of every control.

  • For partners and practice managers

    How Cast & Rule protects your clients' data

    A plain-English guide for partners and practice managers. It covers where client data lives, who can see it, what the AI can and can't do, the partner's ruling, the Ledger, a lost laptop, and how Cast & Rule helps you show you meet your ICAEW and UK GDPR duties.

    Read

  • For iT leads, security reviewers and auditors

    Cast & Rule security architecture

    For IT leads and auditors: Cast & Rule's trust boundaries, data flows, identity and credential custody, least-privilege connectors, prompt-injection defences, egress control, the tamper-evident Ledger, encryption, key management, supply-chain integrity, what we build on, incident response, retention and erasure, and sub-processors, each with its status.

    Read

  • For partners, practice managers and IT leads

    Security questions partners and IT leads ask

    Direct answers to twelve security questions about Cast & Rule: where client data is held, what leaves the practice, model training, sign-off, the Ledger, lost machines, prompt injection, sub-processors, retention and connections.

    Read

Status, control by control

Each control, what it does and its status. Built works in our development build; In build is partly working; Planned is next in line.
What it doesHow it worksStatus
Runs on your hardware
Client files are processed on local hardware the practice controls, on macOS.
Tell me more on trust boundaries (opens in a new tab)
Built
Signs every task
Our control service signs each task, and the agent checks that signature against the permissions your practice accepted.
Tell me more on supply-chain integrity (opens in a new tab)
Built
Shows later changes
The Ledger shows when a record it has already checked was changed later.
Tell me more on the tamper-evident Ledger (opens in a new tab)
Built
Gives each machine its own key
Each machine creates its own identity key. The private key never appears in settings, on the network, in a log or in a database.
Tell me more on identity and credential custody (opens in a new tab)
Built
Keeps documents from granting permissions
A document can't grant permissions. Every output still goes to a person to check, because hostile content can sway an answer.
Tell me more on prompt-injection defences (opens in a new tab)
Built
Revokes a lost machine
Revoking a lost machine blocks its later requests to our service. It doesn't erase the files on it.
Tell me more on incident response (opens in a new tab)
Built
Holds work for the partner
Any action that sends, files, posts, pays or deletes in an outside system needs a partner's approval of that exact action.
Tell me more on least-privilege connectors (opens in a new tab)
In build
Encrypts results
Results your rules allow off the machine are encrypted before they leave: with keys we hold today, so we can read them, and next with a key only your practice holds.
Tell me more on encryption (opens in a new tab)
  • In buildWith our keys
  • PlannedWith your practice's key
Controls the agent's connections
Control and logging of every connection the agent makes. Other apps on the machine are outside their scope.
Tell me more on egress control and logging (opens in a new tab)
In build
Reads client systems
Read-only connections to Xero, Microsoft 365, Companies House and HMRC, one client per connection.
Tell me more on least-privilege connectors (opens in a new tab)
Planned
Keeps each client apart
Each client's records sit in their own encrypted Strongroom store, under their own key.
Tell me more on encryption (opens in a new tab)
Planned
Reports what left
A report, per period, that shows what left the machine through Cast & Rule.
Tell me more on the tamper-evident Ledger (opens in a new tab)
Planned
Publishes the paperwork
The list of suppliers who handle data, a diagram of where data flows, the full statement of what is never used for training, and the exact list of what the Ledger logs.
Tell me more on sub-processors (opens in a new tab)
Planned

Your professional obligations

Cast & Rule is built to help your firm meet these duties.

ICAEW Code of Ethics, section 114

Confidentiality, including inside the firm. ICAEW issued a reminder on 28 July 2026.

ICAEW guidance on generative AI

Confidential client data must not go into public AI tools.

UK GDPR

Limits on what each task can reach, an encrypted store for each client's records, a record of what the AI did and partner review.

What stays with the accountant

Cast & Rule isn't an accountancy practice. Your firm keeps the client relationship, the professional judgement, the tax treatment and the sign-off. Directors still approve company accounts, and clients still approve their returns.

Who handles data, and where it flows

We set out the list of suppliers who handle data, with a diagram of where it flows. It covers hosting for our control service and a cloud-model route used only if your practice turns it on. Where a connection needs login details processed off the machine, we say where that data flows, and who is involved, before it's used.

Questions partners ask about security

Where do the models run?

On local hardware the practice controls. A cloud model runs only where your rules allow it for a task, after identifiers are replaced on your machine. The security architecture sets out where models sit and how they connect.

Does using Cast & Rule meet our ICAEW obligations?

No tool does that for you. Cast & Rule is built to help with confidentiality under ICAEW Code section 114 and ICAEW's generative-AI guidance. The duties stay with your firm.

Who are your sub-processors?

We set out the list of suppliers who handle data, with a diagram of where it flows. It covers hosting for our control service and a cloud-model route used only if your practice turns it on. Where a connection needs login details processed off the machine, we say where that data flows, and who is involved, before it's used.

One practice first

Start with one workflow, over six weeks, with us alongside

For a UK practice of 5 to 20 staff, with a partner who'll own the review. We run one workflow, measure it before and after, and agree in writing how it ends. Send an enquiry or email us today.

Contact us