Your books are sensitive. We treat them that way.
How we protect your data
Roitor CPA operates a PIPEDA-compliant workflow and is regulated by CPA Ontario. The core controls below apply to every client file, regardless of package tier.
Encrypted client portal
All document exchange between you and Roitor happens inside a secure, encrypted client portal — never as an email attachment. The portal logs every upload and download for audit purposes.
Multi-factor authentication (MFA)
MFA is required on every system the firm uses — Google Workspace, QuickBooks Online, Xero, our tax filing software, and the client portal. A password alone is not enough to access your file.
CPA Ontario regulated
As a CPA Ontario member, Varun is bound by the profession's Code of Professional Conduct, including strict rules around confidentiality, file security, and conflict-of-interest checks.
PIPEDA-compliant workflow
We follow Canada's Personal Information Protection and Electronic Documents Act — collection is limited to what's necessary for the engagement, access is need-to-know, and retention is managed under professional standards
Secure cloud-based infrastructure
Our books, tax files, and working papers live on enterprise cloud platforms with AES-256 encryption at rest and TLS 1.2 or higher in transit. We do not store sensitive financial data on local laptops. [VERIFY — confirm actual encryption standards used by QBO, Xero, Google Workspace, and the portal vendor before publishing these specs
No sensitive docs over email
We do not accept tax slips, bank statements, or government correspondence over email. If you send one by mistake, we'll ask you to re-upload via the portal