Claremont SecurityManaged compliance · Enterprise AI protection
Advisory, oversight, and compliance

Services

You hold records people cannot afford to have exposed.

You are expected to prove you protect them.

Four stages, in order. Read the strip below and you have the shape of the whole engagement.

Accounting and tax firms, wealth managers and financial advisors, law firms, mortgage brokers, and medical practices. Who we work with →

  1. 01Conversation

    What you hold, and what is already in place

    Thirty minutes on your vendors, your staff and your Microsoft tenant. Nothing is touched and nothing is sold. If you do not need us yet, that is what we tell you.

    Fee none · Thirty minutes

  2. 02Assessment

    Baseline Security Assessment

    Two weeks of looking from the day we get access. We change nothing while we assess, which is what keeps the findings honest. For firms that need proof rather than paperwork.

    Fixed fee · credited in full against the engagement that follows, if it starts within 90 days

  3. 03Remediation

    Gaps closed in sequence, highest risk first

    Worst first, in the order the list says. Scheduled around your season, not through it. Each control goes in together with the evidence that it is working.

    Fee fixed per engagement · engagements and fees

  4. 04Standing

    One advisor who answers for it in writing

    Client and vendor questionnaires answered with the evidence behind each one, and a quarterly review with your leadership. That review is the only standing commitment.

    Fee monthly · cancellable at renewal

Scope

The three categories

Who each one is for, what it needs from you, and what you get. Fixed fee wherever the scope is fixed.

// Category_01
Category I

Secure AI Integration (Microsoft Copilot)

Your staff will use AI.The only question is whether it happens somewhere you control, or in a personal ChatGPT account with a client's return pasted into it. Until Microsoft commits to U.S.-only processing and the firm can show who reaches the data, Claremont's position is that client tax return information goes into Microsoft 365 Copilot only with each client's consent.

Built forFirms rolling out Microsoft 365 Copilot. Or firms that just found out staff are already using public AI with client work.
RequiresMicrosoft 365 Business Premium, plus a Copilot licence for each person who uses it. Copilot is a paid add-on. No Microsoft 365 business plan includes it.
OutcomeAI in daily use under your firm's Microsoft agreement, and a record of who used it for what.
IPermission review before rollout
  • Copilot shows a person exactly what that person could already open, so the permission work comes first, never after
  • SharePoint and OneDrive checked against who should have what, before Copilot is switched on
  • It is rarely the AI. It is the folder somebody shared with the whole firm three years ago and forgot
IITenant boundary and data loss prevention
  • Microsoft commits to storing prompts and responses in the United States for U.S. tenants, not yet to running the AI only there
  • Prompts and responses are not used to train the underlying models
  • Staff see the warning while they are still typing, not in a report a month later
IIIGoverned agents
  • The Firm Assistant and the Morning Brief for every firm, and one agent built for the work your practice does
  • Fixed output standards and a person's review. Nothing any of them writes sends itself
  • Anything that has to go outside the tenant goes through the Clean Room, which is free
What you walk away with
Permission review before rolloutA list of everything that is over-shared, named by site and library.
Tenant boundary and data loss preventionThe deployment scoped to your tenant, the training opt-outs verified, labels and policies switched on, and one page saying where your data can and cannot go.
Governed agentsAll three set up for your firm, audit logging so AI use is on the record, and one page per agent saying what it may do and what it must refuse.
// Category_02
Category II

AI Oversight and Virtual CISO

Too small to justify a security hire.Too exposed to go without one. We lock down who can sign in, check what your existing tools actually cover, and answer for your security in writing.

Built forPractices of ten to twenty-five staff, nobody whose job is security, and a growing pile of client security questionnaires.
RequiresMicrosoft 365 Business Premium. Business Standard has neither Intune nor Defender for Business, so this cannot be delivered on it.
OutcomeA defended firm with coverage you can point at, and one advisor who answers the questionnaires, sits down with your leadership once a quarter, and picks up the phone when something looks wrong.
IIdentity and access control
  • Multi-factor authentication on every account, the admin and service accounts included
  • Those are the accounts that usually get an exemption, and the exempted group is where the real gap lives
  • Offboarding runs from a written procedure rather than from memory
IIEndpoint coverage verification
  • On Business Premium you already pay for Defender. The work is proving it reaches every machine
  • The problem is rarely a missed detection. It is the three laptops nobody knew were unmanaged
  • Update status confirmed at the machine, not read off a dashboard
IIIWhat maintenance adds
  • New agents reach your tenant in the quarter they ship
  • New gallery prompts and short notes on what Microsoft changed, as they are written
  • One quarterly review with your leadership, which is the only standing commitment
What you walk away with
Identity and access controlSign-in rules switched on with every exemption written down, a register of who holds admin rights, and an offboarding checklist that cuts access on day one.
Endpoint coverage verificationDefender set up to a written standard, coverage checked against your staff list, and update status confirmed machine by machine.
What maintenance addsEvery control at deployment rather than held back for a higher tier, and a setup that improves instead of one frozen on the day it was built.
// Category_03
Category III

Compliance Documentation

A firm can be secure and unable to prove it.That gap is the exposure. We turn what you already do into the record a regulator expects to read.

Built forTax and accounting firms under the FTC Safeguards Rule and the IRS WISP requirement. Especially the ones whose plan is a template nobody has opened.
OutcomeA written record of your security program that holds up when someone asks for it. Where an assessment is run, a list of gaps with owners and dates.
IThe Safeguards Pack
  • Written for your firm instead of downloaded, from one 45-minute call on your vendors, your staff and your tenant
  • Your IT provider named as the owner of each control
  • Three weeks, fixed fee. Nothing in your systems is touched
IIBaseline Security Assessment
  • For firms that need proof, not just paperwork. Two weeks of looking from the day we get access
  • Nothing is touched. Fixed fee, credited in full against the engagement that follows, if it starts within 90 days
  • This is stage 02 of the engagement above, not a second purchase
III§7216 consent review
  • For firms using an AI tool, or sending returns to preparers outside the United States
  • We list what your client consent form must mention for each AI tool you use
  • The wording itself comes from your lawyer or your tax software
What you walk away with
The Safeguards PackA Written Information Security Program, an incident response plan with one practice run, a register of the vendors who touch client data under 314.4(f), and an AI acceptable use policy.
Baseline Security AssessmentA list of every gap against 16 CFR Part 314 and IRS Publication 4557, each with an owner by role and a date. Plus a straight answer on whether you are ready for Microsoft 365 Copilot.
§7216 consent reviewWhat your client consent page has to name, for each provider you use, so your counsel or your tax software's consent form can cover it. That includes anyone outside the United States who may receive or view return information, a provider's support staff included. For Form 1040 clients the Social Security number stays out even with consent.
Limits

What we do not do

Stated plainly, because the gap between what a small firm needs and what one outside advisor can deliver is exactly where engagements go wrong.

We do not monitor a console around the clock

The platform monitors continuously. We review and respond to alerts on a defined business-hours cadence. We do not run a help desk or an around-the-clock response team. Where a firm needs eyes on a screen overnight it needs a managed detection provider, and we will say so rather than sell around it.

We do not deploy patches

Category II is oversight and evidence. Known-exploited vulnerabilities are surfaced and tracked to closure with per-endpoint evidence, and your IT provider does the deploying.

We do not audit, certify or attest

Those are terms of art belonging to licensed firms. Claremont performs assessments and produces documentation you can hand to whoever asks.

We do not run phishing simulations

No platform for it is in place. If that is a requirement, say so early and we will tell you who does it.

We do not take more than two engagements at once

Two simultaneous engagements is the honest ceiling. If the calendar is full you will be told, not queued quietly.

The rest of it

How the function is structured from outside, what it covers, the cadence it runs on and what it runs on. The fractional model brief →

Start with a conversation, or run the AI Exposure Check on your own tools and send us what it shows.

Talk to us Run the instrument
16 CFR 314.4(j) · 30 days to notify the FTC of a notification event of 500 or more consumers16 CFR 314.6 · below 5,000 consumers, 314.4(b)(1), (d)(2), (h) and (i) do not apply; every other paragraph does16 CFR 314.2(m) · encrypted customer information with the key intact is not a notification event16 CFR 314.4(c)(5) · multi-factor authentication for any individual accessing any information system, unless an equivalent control is approved in writing16 CFR 314.4(c)(6) · secure disposal within two years of last use, unless a named exception applies16 CFR 314.4(f) · service providers bound by contract to maintain safeguards, and reassessed26 U.S.C. §6713 · $250 per disclosure of return information, $10,000 per calendar year26 CFR §301.7216-2(d)(1), (d)(3) · return information goes without consent only to a preparer located in the United States; a contractor’s employee abroad who only views it puts the disclosure outside the United States