Security held to the standard our customers hold themselves to.

Client documents and return information pass through Proxara, so the firm decides what any AI may reach, and can see and undo that decision at any point.

The firm’s own environment
Documents and client records stay hereA model runs here, on the firm’s own computeThe firm holds the encryption keys
Amazon Web ServicesMicrosoft Azure
Where work begins
ClaudeChatGPTMicrosoft TeamsA firm-built agent
The Work API
One authorized piece of workOne purpose, one policy, one firm

What the firm’s Microsoft administrator actually does.

One approval, and four screens in the firm’s own tenant that undo it. Nothing installs, no certificate is trusted, and there is no credential to hold.

For the Microsoft administrator
Microsoft
admin@contoso.com
Permissions requested
Review for your organization
Proxara Connect
Proxara, Inc.
This application is not published by Microsoft or your organization.
This app would like to:
Read user mail
Read user calendars
Read user chat messages
Read user channel messages
Read all files that user can access
Read user's tasks and task lists
Sign in and read user profile
View users' basic profile
If you accept, this app will get access to the specified resources for all users in your organization. No one else will be prompted to review these permissions.
Accepting these permissions means that you allow this app to use your data as specified in their terms of service and privacy statement. You can change these permissions at https://myapps.microsoft.com. Show details
Does this app look suspicious? Report it here
CancelAccept

Microsoft’s own screen, opened from a link. Every permission on it is delegated and read-only, and it covers the organization by construction, which is why the screen carries no checkbox.

Read the screen, line by line

One firm to an environment.

Each firm gets a private cloud account of its own, on AWS or Azure, with its own network and its own encryption. Nothing about one firm sits in a shared environment with another.

  • 01

    A private cloud account

    On AWS or Azure, from a hardened template, and never shared with another firm.

  • 02

    Who controls it is written down

    The account owner, the encryption keys, what the Proxara role may do, how the firm revokes it, and the exit.

  • 03

    Four lanes, and approved work picks one

    Raw material is parsed and computed inside the firm. A managed endpoint on a private link is still outside it.

  • 04

    The gateway holds nothing

    No source credential, no store permission, no mapping, no ability to act.

The firm picks the region. Every subprocessor is named in the trust center.

CUSTOMER VPC · DEDICATED AWS ACCOUNTREQUEST SOURCESemployee + AI toolapproved agentworkspacescheduledENTRYCONNECTORSKarbon · M365 · SharePointWORK APIfirm agents · scheduledWRITE BOUNDARYauthorizeexecuteverifyCUSTOMER-LOCAL WORKpurpose · identity · policy · local modelKMS keysRDS · the recordS3 · archivesDEST 01approved modelDEST 02AI hostDEST 03firm agentsproposal↘ approved claimssingle tenant · raw material stays local

Five checks, and any one of them can stop the work.

Each check can narrow the work or stop it. None of them can widen what the firm allowed. Where coverage falls short the work stays local, drops that source on the record, or asks the preparer one question.

A missing or reordered step is visible.

Each step is written as it happens and chained to the one before it, so a gap or a reordering shows up. The rows carry counts, categories and reference codes, never content. An export opens in a reviewer’s own tools rather than ours.

We hold as little of the firm as we can.

Encrypted at rest

Each identity is individually encrypted and keyed.

Crypto-shredding

for erasure requests

Erase one key to delete one identity.

Separated by account

One firm never shares an environment with another.

What we get

  • What the work was, and who approved it.
  • Which systems it read, and which it was kept out of.
  • What left the firm, and where it went.
  • What changed in the end, and whether the source system agreed.

What we never get

  • Any system the firm did not connect.
  • What was asked, what was read, or any client name.
  • A standing copy of the firm. Nothing is mirrored.
  • Client material on our side. We get counts and codes.

Retention is a class, not one number.How retention is setRetrieved material, stand-in mappings, clear artifacts and the record each carry a purpose, an expiry and a method of erasure. Source systems stay authoritative: Proxara is a processing and execution boundary, not the firm’s system of record.

From first touch to deployment.

  1. 01Configure

    Choose AWS or Azure, the customer-local model, firm policy, and the scope of the deployment.

  2. 02Approve

    Contracting, security review, Microsoft administrator consent, and the authorizations for each system.

  3. 03Deploy

    Proxara stands up inside the firm’s own private network, under the keys the deployment record names.

  4. 04Activate

    Connect the systems of record, then open the work to the assistants the firm already runs.

Systems of record
KarbonMicrosoft 365SharePointCRM and tax systems
Where the work begins
ClaudeChatGPTTeamsSlack

The controls, and what they map to.

Real parameters, and a status rather than a badge. Citations in the trust center.

Proxara does not provide tax or legal advice. Firms should confirm the treatment of their own workflows with their counsel.

Public documents for vendor diligence.

Signed security questionnaires are available on request under NDA.

Ask us anything about this.

security@proxara.ai