BeforeMay docs
Security, data & AI

Data flow and processing locations

Distinguish Australian storage, overseas AI processing, local conversion and identity capture.

Source reviewed Security and privacy documentation

The Privacy Policy describes documents and account data stored at rest in Australia and our own processing services in Sydney. Some external processing happens overseas. Use the product-specific route below when assessing your practice's data.

Workpapers

Workpapers data flowOriginal files stay in Australian private storage. Supported outbound text and file copies pass identifier controls before configured AI processing overseas; delivered work still needs accountant review.

Loading diagram…

Diagram source
flowchart TB
  accTitle: Workpapers data flow
  accDescr: Original files stay in Australian private storage. Supported outbound text and file copies pass identifier controls before configured AI processing overseas; delivered work still needs accountant review.
  U[Practice: authorised upload]
  H[Practice: accountant review]
  subgraph AU[Australia: source evidence]
    S[(Private source files)]
    R[Document recognition]
    G[Outbound identifier controls]
  end
  subgraph External[External AI: location depends on provider]
    AI[Configured analysis, build and review stages]
  end
  subgraph Delivery[Australia: workpaper process]
    W[Build, review and delivery policy]
    O[(Delivered workbook)]
  end
  U --> S --> R --> G
  S -->|Supported file copies| G
  G -->|Processed text, context and copies| AI
  AI -->|Stage results| W
  W --> O --> H
  class G,W control

This is the Workpapers route at a boundary level, not a network trace. The outbound controls differ between text and file formats; they do not make all remaining case information anonymous. Review may be disabled or degraded, and delivery can include outstanding findings. See AI processing and human review.

Our own recognition and identifier-removal services run in Australia. Before outbound AI processing, supported text and source files pass the relevant identifier controls. Case context, recognised text and processed source files can be provided to the configured AI services. The accountant's original source file remains a practice record; the outbound copy has a different purpose.

The policy names possible AI processing in the United States and China. Provider choice can vary by stage and practice configuration. Ask which providers apply to your practice; do not infer that from an old model name or the location of the worker that makes the request.

Other products

FlowFile or content processingWhat can be stored
Clients and client filesAuthorised client/practice upload and previewClient records and filed documents
OutlookMail is read from the member's connected Microsoft mailboxEnvelope index; a stored file when mail or attachments are explicitly or automatically filed
SignPDF stored for the request and signed through the request-specific pageSource/signed PDF, request state and signing events
VerifyThe person provides ID images and biometric captures directly to Didit in the EUBeforeMay's result summary and due-diligence records; not those biometric images
BAS ReviewCSV transaction rows parsed in the browserClient/period, filename, aggregate figures, counts and decisions keyed by hashed finding identifiers
SiftDigital PDF conversion in the browserThe conversion keeps the work in browser memory; you download the result
CloakDigital PDF detection/redaction locally; a separate Australian OCR route for scansCheck the selected route's notice and API arrangement

Providers and analytics

The policy's provider table includes infrastructure, AI, payments, email, identity and analytics providers. That table is the maintained list of processing purposes and locations; a service listed there is not necessarily used for every task.

Analytics are separate from document processing. The policy describes product identifiers and page/error information that analytics can receive, and states that client documents and their contents are not supplied to analytics. Optional third-party sign-in and mailbox connections have their own provider interaction.

Verify's distinct boundary

Verify identity evidence boundaryThe person gives ID images, selfie and liveness captures directly to Didit in the EU. BeforeMay stores a result summary and due-diligence records for the practice to assess.

Loading diagram…

Diagram source
flowchart TB
  accTitle: Verify identity evidence boundary
  accDescr: The person gives ID images, selfie and liveness captures directly to Didit in the EU. BeforeMay stores a result summary and due-diligence records for the practice to assess.
  P[Person opens a Verify request] --> N[Identity notice and consent]
  N --> D[Didit: identity capture and check in the EU]
  D -->|Result summary| B[(BeforeMay check record)]
  B --> F[Practice assesses and records due diligence]
  D --- I[ID images and biometric captures stay with Didit]
  class N control

The connector receives a provider notification and re-reads the result using its server credentials. The summary route above does not carry the ID images, selfie or liveness video into BeforeMay's private storage.

Workpapers' AI redaction does not apply to ID evidence a person gives directly to Didit: the provider needs to read the document to perform the check. Read the identity notice before asking a client to proceed. See Verify and the identity-specific section of the Privacy Policy.

On this page