Security · For partners, practice managers and IT leads

Security questions partners and IT leads ask

Built means working in our development build. In build means partly working, and being finished for release. Planned means specified, and next in line to build. For the detail behind these answers, see the security overview and the security architecture.

Two colleagues look through a Cast & Rule security booklet together at a wooden desk.

Where is our clients' data held?

Client content is processed on local hardware your practice controls. Built; macOS only. Client isolation and the Strongroom's encrypted client stores are Planned, as is running the whole system on your machine. Our control service doesn't store client documents, but authorised results may still contain client information. Result encryption is In build. In today's development build, we hold the decryption keys, so we can access those results. Practice-only decryption is Planned.

What leaves the practice machine?

The agent sends the operational metadata and results your Rules permit. Built task-permission controls limit authorised agent work. Built. Full agent connection controls are In build; other apps are outside their scope. Where your Rules let a result leave the machine, it's encrypted first. In today's development build, we hold the keys. In build.

Is our client data used to train AI models?

No. Cast & Rule doesn't use your clients' data to train AI models. The full statement of what we never use for training is Planned.

Can the AI send, file or post anything on its own?

No. The product can't write to, send to or file with any outside system today. When that capability arrives, every such action will need a named partner's ruling (their sign-off) on that exact action. Ruling is In build.

What exactly does a partner approve?

One exact piece of work, with the evidence beside it: what would happen, where any data would go and the steps that produced it. If anything changes after the ruling, the approval lapses. The work returns for a fresh decision. The ruling records the partner's name, qualification and the time. Ruling is In build.

Can the Ledger be edited after the fact?

Each entry is locked to the one before it (hash-chained), so a later change would show up. We check the latest entry regularly. The Ledger can reveal changes to records already checked by our service. Built. This is tamper evidence, not tamper prevention. The Ledger never holds client content itself.

What happens if a practice laptop is lost or stolen?

Revoke the machine from the administration screen, without needing its co-operation. Revocation blocks the machine's future requests to our service. Built. It doesn't erase local files or instantly stop offline processing. The machine's identity key can't be copied off its hardware. In build. Revoking connector access at the supplier and per-client encrypted records are Planned.

How does Cast & Rule handle instructions hidden in client emails or documents?

Built controls restrict task permissions. Documents can't grant permissions, but hostile content may influence answers. Outputs still need review. Tasks run only from signed definitions. Built. An operating-system sandbox for task work is In build.

Is your security home-grown?

The controls are ours. The cryptography, policy language and detection components under them are well-reviewed open source under permissive licences, and we don't write our own cryptographic algorithms (see the security architecture, section 11). An independent review of the whole is Planned. A full component list under a non-disclosure agreement is Planned.

Who are your sub-processors?

We'll publish the list, with a data-flow diagram, before launch. It will cover hosting for the control service and a cloud-model route used only if your practice turns it on. Where a planned connection needs off-device processing of authentication information, we'll declare the data flows and any providers involved before use.

Does erasing a client's data conflict with our AML record-keeping?

It doesn't have to. Retention and erasure controls are Planned and need checking before client use. Cast & Rule separates erasure from legal retention. CDD records are usually kept for five years after the relationship ends; relevant transaction records are usually kept for five years from completion (HMRC guidance). Records under that hold would move to a restricted area outside everyday AI use until the obligation ends. Your practice sets the schedule.

Which of our systems can Cast & Rule connect to today?

None yet. Connections to Xero, Microsoft 365, Companies House and HMRC are all Planned. They start read-only, with one client organisation per connection. HMRC submission stays in your existing MTD-recognised software until a direct connection is built and documented.

One practice first

Start with one workflow, over six weeks, with us alongside

For a UK practice of 5 to 20 staff, with a partner who'll own the review. We run one workflow, measure it before and after, and agree in writing how it ends. Send an enquiry or email us today.

Sources

Show all 1 sourcesHide sources
Contact us