Proxaradocs
Guides/Start here

How Proxara works

What the AI sees, what it never sees, and where the real names live.

Updated August 2026

The AI the firm uses receives no client names, no identifiers and no return figures, only stand-ins and approved facts. The real records stay in the firm, and nothing with a consequence happens without a person.

What the model sees

ReceivesNever receives
Typed claims: a requirement's state, a document kind, a date, a threshold crossedNames, addresses, identifiers, account numbers, return figures
Stand-ins for people, organizations and recordsThe real values, or the mapping
An opaque reference to the private viewDocuments, mail bodies, attachments, filenames, recipients

The payload is built only from claims the firm's policy approved, never from a document with the sensitive parts removed, and what cannot be accounted for never leaves: the work stays local, drops that source, or stops. The system's worst case is less useful, never less private.

Where the real names live

The private view opens from the conversation under your Microsoft work sign-in, bound to you and this piece of work. Each stand-in becomes the real name there. The model cannot read it, and a stand-in copied into another conversation resolves to nothing.

What waits for a person

Reading, drafting and reversible internal updates run on their own. A client send, a filing, a payment or finalising a return waits for a named person, who sees the real recipient and content before confirming. The change is then read back from the system that owns it; a half-finished job is repaired only where it failed, and a message that already went out is never sent twice.

One piece of work, start to finish
StageWhat happens
PurposeThe approved work, client and period
RetrievePermitted context, on the employee's own credential
ReadDocuments become typed units inside the firm
Join and computeRecords link where the work permits; exact figures stay local, never perturbed
ReleaseApproved claims go out, or the work stays local
Plan and bindThe model proposes typed steps; the firm resolves the real client and recipient
Execute and verifyRuns on the firm's own credentials, then the provider is read back
RecordPurpose, sources, releases, approvals, effects, outcome
Where each part of the work runs
LaneWhat it handles
Deterministic, inside the firmMatching, extraction, calculation, thresholds, binding, readback
A model inside the firmClassification, sensitive reasoning, private drafting
An approved external modelDrafting, organizing, sequencing, choosing from approved actions
A separately authorized routeOne purpose and data class the firm configured deliberately

The model inside the firm has no internet route and no provider credentials. No lane quietly widens into the next, and a private network link to a managed model is not customer-contained.

Stand-ins, precisely

A stand-in such as [Person_0CE2473EA47B] is derived under a firm-held key from a random reference, never from the name it replaces.

It holds steady inside one piece of work, so multi-step work stays coherent, then rotates at the boundary of that work, its purpose or destination, so nothing assembles across tasks or days.

The mapping stays encrypted inside the firm and is erased cryptographically, leaving the original unrecoverable even from a copied backup.

Releases are judged against what has already accumulated in that destination: a few ordinary facts on one reference can identify a taxpayer.

Documents and scans

PDFs, scans, photographs, spreadsheets and mail attachments are read inside the firm before any release decision, never by an outside service.

Every extracted value keeps its page and cell, so a preparer can click a figure and land where it came from. Coverage is stated per file, and an unreadable region is treated as unsafe rather than empty.

The record

Every piece of work leaves one: what was consulted, what was released and to which destination, what stayed private, who confirmed a consequential effect, and what the source system confirmed back.

It holds counts and categories, never client content, so it cannot follow one client from one job to the next. It is what a firm exports when a reviewer asks what left the boundary.

Proxara does not provide tax or legal advice. Firms should confirm the treatment of their own workflows with their counsel.

Where to go next

To understandRead
First requests that work on day oneWhat to ask for
The full section 7216 analysisSection 7216
What a leader sees and controlsThe console