Services
You hold records people cannot afford to have exposed.
You are expected to prove you protect them.
Four stages, in order. Read the strip below and you have the shape of the whole engagement.
Accounting and tax firms, wealth managers and financial advisors, law firms, mortgage brokers, and medical practices. Who we work with →
- 01Conversation
What you hold, and what is already in place
Thirty minutes on your vendors, your staff and your Microsoft tenant. Nothing is touched and nothing is sold. If you do not need us yet, that is what we tell you.
Fee none · Thirty minutes
- 02Assessment
Baseline Security Assessment
Two weeks of looking from the day we get access. We change nothing while we assess, which is what keeps the findings honest. For firms that need proof rather than paperwork.
Fixed fee · credited in full against the engagement that follows, if it starts within 90 days
- 03Remediation
Gaps closed in sequence, highest risk first
Worst first, in the order the list says. Scheduled around your season, not through it. Each control goes in together with the evidence that it is working.
Fee fixed per engagement · engagements and fees
- 04Standing
One advisor who answers for it in writing
Client and vendor questionnaires answered with the evidence behind each one, and a quarterly review with your leadership. That review is the only standing commitment.
Fee monthly · cancellable at renewal
Where firms usually start
The three categories
Who each one is for, what it needs from you, and what you get. Fixed fee wherever the scope is fixed.
Secure AI Integration (Microsoft Copilot)
Your staff will use AI.The only question is whether it happens somewhere you control, or in a personal ChatGPT account with a client's return pasted into it. Until Microsoft commits to U.S.-only processing and the firm can show who reaches the data, Claremont's position is that client tax return information goes into Microsoft 365 Copilot only with each client's consent.
- Copilot shows a person exactly what that person could already open, so the permission work comes first, never after
- SharePoint and OneDrive checked against who should have what, before Copilot is switched on
- It is rarely the AI. It is the folder somebody shared with the whole firm three years ago and forgot
- Microsoft commits to storing prompts and responses in the United States for U.S. tenants, not yet to running the AI only there
- Prompts and responses are not used to train the underlying models
- Staff see the warning while they are still typing, not in a report a month later
- The Firm Assistant and the Morning Brief for every firm, and one agent built for the work your practice does
- Fixed output standards and a person's review. Nothing any of them writes sends itself
- Anything that has to go outside the tenant goes through the Clean Room, which is free
AI Oversight and Virtual CISO
Too small to justify a security hire.Too exposed to go without one. We lock down who can sign in, check what your existing tools actually cover, and answer for your security in writing.
- Multi-factor authentication on every account, the admin and service accounts included
- Those are the accounts that usually get an exemption, and the exempted group is where the real gap lives
- Offboarding runs from a written procedure rather than from memory
- On Business Premium you already pay for Defender. The work is proving it reaches every machine
- The problem is rarely a missed detection. It is the three laptops nobody knew were unmanaged
- Update status confirmed at the machine, not read off a dashboard
- New agents reach your tenant in the quarter they ship
- New gallery prompts and short notes on what Microsoft changed, as they are written
- One quarterly review with your leadership, which is the only standing commitment
Compliance Documentation
A firm can be secure and unable to prove it.That gap is the exposure. We turn what you already do into the record a regulator expects to read.
- Written for your firm instead of downloaded, from one 45-minute call on your vendors, your staff and your tenant
- Your IT provider named as the owner of each control
- Three weeks, fixed fee. Nothing in your systems is touched
- For firms that need proof, not just paperwork. Two weeks of looking from the day we get access
- Nothing is touched. Fixed fee, credited in full against the engagement that follows, if it starts within 90 days
- This is stage 02 of the engagement above, not a second purchase
- For firms using an AI tool, or sending returns to preparers outside the United States
- We list what your client consent form must mention for each AI tool you use
- The wording itself comes from your lawyer or your tax software
What we do not do
Stated plainly, because the gap between what a small firm needs and what one outside advisor can deliver is exactly where engagements go wrong.
The platform monitors continuously. We review and respond to alerts on a defined business-hours cadence. We do not run a help desk or an around-the-clock response team. Where a firm needs eyes on a screen overnight it needs a managed detection provider, and we will say so rather than sell around it.
Category II is oversight and evidence. Known-exploited vulnerabilities are surfaced and tracked to closure with per-endpoint evidence, and your IT provider does the deploying.
Those are terms of art belonging to licensed firms. Claremont performs assessments and produces documentation you can hand to whoever asks.
No platform for it is in place. If that is a requirement, say so early and we will tell you who does it.
Two simultaneous engagements is the honest ceiling. If the calendar is full you will be told, not queued quietly.
How the function is structured from outside, what it covers, the cadence it runs on and what it runs on. The fractional model brief →
Start with a conversation, or run the AI Exposure Check on your own tools and send us what it shows.
Talk to us Run the instrument