Security and data use
Client data gets handled like the regulated material it is.
Referring a client means trusting us with their financial life. These controls were designed in from the start, and they're published so your firm can check them without booking a call. Five separated planes underneath, with the workflow plane never touching a tax document.
The controls
Five separated planes. Named, published, diligenceable.
1 · Workflow plane (GHL)
Client-relationship metadata, scheduling, campaign state, and secure hand-off links. Never a tax return, never a source document, never a working paper.
2 · Tax-document plane
Returns, source documents, and working papers live inside the professional firm's controlled environment: McGee's Consulting or your firm's own tax stack. Nothing leaves it without §7216 consent tied to the specific flow.
3 · Identity and access plane
Role-based access with MFA, WISP-governed provisioning, vendor review, and incident response. Access changes are logged; every session is attributable to a specific person.
4 · AI-tool plane
Session-scoped, disclosed on /ai-disclosure by category. Output that carries professional weight is reviewed by a named professional before it is relied on. AI accelerates the work; it does not sign it.
5 · Audit and log plane
Immutable trail across the four planes above: consent, access, prompts, and hand-offs. Exportable on request for your firm's own records.
The workflow plane, specifically
What GHL sees. What GHL never sees.
The growth rail (GHL) runs the client-relationship layer. It doesn't touch tax material. Table below is the plain enumeration your firm's security review will ask for.
GHL sees
GHL never sees
Questions from your firm's security review?
See how delivery is governed, or read exactly which AI tools touch what data.

