Security & working with your firm

Your client stays your client.

MatchPass provides reconciliation engineering. The accounting firm retains the client relationship, professional judgment, month-end close and financial reporting.

This page describes how we scope work, what access we ask for, and how data is handled. Where something is a commitment we make in the engagement agreement rather than a certification we hold, it is written that way.

01

Scope and responsibility

The division of work is set out in writing before an engagement begins, and it does not move without a change order.

Your firm

  • Client relationship and communication
  • Accounting judgment and classification
  • Month-end close and financial statements
  • Approval of exception treatment

MatchPass

  • Reconciliation workflow engineering
  • Repeatable match and rollup logic
  • Exception dashboard and scheduled runs
  • Agreed maintenance as sources and rules change

MatchPass does not provide the bookkeeping engagement and does not take over the client relationship.

02

Access we ask for

We work on a least-access basis. The goal at every stage is the minimum access that makes the work possible, and nothing beyond it.

03

Where the workflow runs

An implemented reconciliation workflow can run on the client's own infrastructure, so the matching engine and exception dashboard sit inside systems the client already controls.

Runs can be scheduled so the reconciliation happens on a defined cadence rather than depending on someone remembering to trigger it.

Being documented

Hosting arrangements where a client prefers MatchPass to operate the workflow, including where that infrastructure is located, are agreed per engagement and are not yet described in a standing policy on this page.

04

Credentials

Credentials are never requested or accepted over email, chat or any other unencrypted channel. Where access is required, it is granted through the platform's own invitation or permission system so that the client's administrator can see and revoke it directly.

Being documented

Our internal credential-storage and authentication practices are not described here yet. Ask directly if your firm needs this confirmed before an engagement.

05

Data retention and deletion

Return and deletion of client data are agreed in writing before work starts, and the process is documented as part of handoff at the end of an engagement.

Working data is limited to what the engagement requires. Where an assessment can be completed from a single period of exports, we do not ask for a full historical extract.

Being documented

A standing retention schedule with fixed periods is not published here yet, because the correct answer depends on the engagement. It is set per contract instead.

06

Logging and audit trail

Matching activity can be logged so that a run can be reviewed line by line after the fact. Each exception carries its reason code and the rule that routed it, which is what makes the output reviewable by an auditor rather than something that has to be taken on trust.

This is a property of the delivered workflow, and what gets logged is agreed as part of scoping.

07

Confidentiality and non-solicitation

Confidentiality is handled through a mutual non-disclosure agreement, and we are glad to sign a firm's own NDA rather than insisting on ours.

Client non-solicitation is part of how we contract on partner engagements. A firm introducing a client is not creating a route for MatchPass to take that relationship.

Before signature

Our standard agreement templates are with counsel for review. Engagement documents are not issued for signature until that review is complete, which does not prevent a conversation, an assessment being scoped, or a firm's own paperwork being used.

08

What we do not claim

MatchPass is a small, new practice. We would rather tell you plainly what we do not have than imply a posture we cannot evidence.

If your firm's own risk process requires any of these, say so early. For some firms the right answer is a subcontracted model where the client data never leaves your environment, and we would rather structure it that way than overstate what we carry.

09

Continuity and handoff

Every implementation ships with documentation of the matching rules, the exception logic and the operating process, and a handoff session with the people who will run it.

The intent is that the workflow remains operable by the firm or the client without MatchPass. A care plan is an option, not a dependency created on purpose.

10

Security questions

If your firm has a vendor review process, send it over and we will answer it directly, including the questions where the honest answer is that we do not have that control yet.

Email karan@matchpasslabs.com or book a call.

Book a Case Fit Call