Security held to the standard our customers hold themselves to.
Client documents and return information pass through Proxara, so the firm decides what any AI may reach, and can see and undo that decision at any point.
What the firm’s Microsoft administrator actually does.
One approval, and four screens in the firm’s own tenant that undo it. Nothing installs, no certificate is trusted, and there is no credential to hold.
Microsoft’s own screen, opened from a link. Every permission on it is delegated and read-only, and it covers the organization by construction, which is why the screen carries no checkbox.
Read the screen, line by lineOne firm to an environment.
Each firm gets a private cloud account of its own, on AWS or Azure, with its own network and its own encryption. Nothing about one firm sits in a shared environment with another.
- 01
A private cloud account
On AWS or Azure, from a hardened template, and never shared with another firm.
- 02
Who controls it is written down
The account owner, the encryption keys, what the Proxara role may do, how the firm revokes it, and the exit.
- 03
Four lanes, and approved work picks one
Raw material is parsed and computed inside the firm. A managed endpoint on a private link is still outside it.
- 04
The gateway holds nothing
No source credential, no store permission, no mapping, no ability to act.
The firm picks the region. Every subprocessor is named in the trust center.
Five checks, and any one of them can stop the work.
Each check can narrow the work or stop it. None of them can widen what the firm allowed. Where coverage falls short the work stays local, drops that source on the record, or asks the preparer one question.
A missing or reordered step is visible.
Each step is written as it happens and chained to the one before it, so a gap or a reordering shows up. The rows carry counts, categories and reference codes, never content. An export opens in a reviewer’s own tools rather than ours.
We hold as little of the firm as we can.
Encrypted at rest
Each identity is individually encrypted and keyed.
Crypto-shredding
for erasure requestsErase one key to delete one identity.
Separated by account
One firm never shares an environment with another.
What we get
- What the work was, and who approved it.
- Which systems it read, and which it was kept out of.
- What left the firm, and where it went.
- What changed in the end, and whether the source system agreed.
What we never get
- Any system the firm did not connect.
- What was asked, what was read, or any client name.
- A standing copy of the firm. Nothing is mirrored.
- Client material on our side. We get counts and codes.
Retention is a class, not one number.How retention is setRetrieved material, stand-in mappings, clear artifacts and the record each carry a purpose, an expiry and a method of erasure. Source systems stay authoritative: Proxara is a processing and execution boundary, not the firm’s system of record.
From first touch to deployment.
- 01Configure
Choose AWS or Azure, the customer-local model, firm policy, and the scope of the deployment.
- 02Approve
Contracting, security review, Microsoft administrator consent, and the authorizations for each system.
- 03Deploy
Proxara stands up inside the firm’s own private network, under the keys the deployment record names.
- 04Activate
Connect the systems of record, then open the work to the assistants the firm already runs.
Karbon
Microsoft 365
SharePointCRM and tax systems
Claude
ChatGPTThe controls, and what they map to.
Real parameters, and a status rather than a badge. Citations in the trust center.
What the rule covers, what the boundary answers, and where consent is still required.
Diligence and confidentiality in AI-assisted work, attributable to a named person.
Approved tools, named users, and what left the firm, for the AI chapter of the WISP.
DPA with SCCs; processing in the region the firm selected.
Service Provider obligations documented in the DPA.
Every permission Connect asks for, and how the firm withdraws it.
Proxara does not provide tax or legal advice. Firms should confirm the treatment of their own workflows with their counsel.
Public documents for vendor diligence.
Signed security questionnaires are available on request under NDA.
IRC § 7216
What the rule says, what it means for AI-assisted tax work, which technical facts Proxara enforces, which deployment assumptions the reading depends on, and which questions belong to the firm’s own tax counsel.
Security
Current autonomous-operator architecture, dedicated-account isolation, local inference, provider authority and readback, Teams delivery and enabled Slack signed-request, exact-identity, and private-result handling, narrow Rocket telemetry, privileged support access, retention, and known limits.
Operator for IT
A concise IT review of the dedicated managed environment, tenant-wide Microsoft roles, the optional signed Slack app and exact identity binding, customer-local model, provider effects, Rocket readback, privileged support, and revocation.
DPA
The Article 28 processor terms for the autonomous operator, including roles, instructions, security, Teams delivery and enabled Slack signed-request and private-result classification, transfers, incidents, confidential Rocket telemetry, retention, and lawful exit duties.
Operator DPIA
A baseline Article 35 assessment of tenant-wide provider access, historical assimilation, local autonomous action, Teams delivery and enabled Slack signed-request and private-intervention handling, privileged managed-service access, telemetry, and residual risk.
Subprocessors
Confirmed AWS infrastructure processing plus the Azure Bot/Bot Framework, enabled Slack signed-request, identity, and private-delivery app, and optional SMTP roles that each Order Form must classify before use.


