Skip to content

Security, independence and quality

The controls a due-diligence questionnaire actually asks about.

Where data rests, who can move it, how access is granted and removed, who reviews the work, and how independence is screened. Stated once, plainly, without certification theatre.

Controls

Expand any group.

Secure VDI
Work is performed inside a virtual desktop environment; source data stays within the controlled session.
Multi-factor authentication
MFA is required for access to delivery environments and firm systems.
Role-based, least-privilege access
Access is granted per named individual, scoped to the engagement, and reviewed.
Approved devices
Delivery work is performed on approved devices only.
Download and printing restrictions
Local download and print are restricted within the delivery environment.

What is not claimed

Absence of a claim is itself information.

Nothing below is asserted anywhere on this site, because supporting documentation has not been verified. If your due-diligence process requires any of them, say so early — the honest answer may be that we are not the right fit yet.

  • SOC 2
  • ISO 27001
  • Cyber-insurance coverage
  • U.S. data residency
  • Zero-trust architecture

Independence and conflict screening

Shah Teelani serves companies directly as well as supporting CPA firms. That makes conflict screening a precondition rather than a formality. Your client list is screened against our engagements before acceptance and again at every scope change. Prohibited non-audit services are not provided to an entity your firm audits, and every potential engagement is subject to independence, conflict, licensing, and professional-standard review.

Quality review

An internal quality review runs before delivery and again after your review notes are cleared, checking documentation completeness, referencing, and evidence that each note was addressed. We do not promise error-free work; we promise that errors are found by a reviewer before they reach yours, and that the ones that get through are logged and fed back into training.

Due-diligence overview

A downloadable security and due-diligence overview will be published here once its contents are approved by the firm. Until then, completed security questionnaires are provided directly during step two of the delivery process.

Verification note. The controls described on this page reflect the environment as described by the firm. Evidence for each control — policy documents, access-review records, and training logs — is provided to CPA firms under NDA during due diligence, and this page will be updated to reference that documentation once it is approved for publication.