Claremont SecurityManaged compliance · Enterprise AI protection
Free for any firm

Tools

One instrument, the Clean Room, two checks, three builders and two references. No account and no sign-in. Everything runs in your browser, except where a tool has a send button and says so. The reference material is free; the guidance is what we sell.

The instrument

AI Exposure Check

Pick the kind of client information and the tool it is going into. Every obligation that attaches lights up on the way there, with the statute and what would clear it. Your tool on the top lane, the governed deployment below, so the difference is the picture.

Open the instrument
Live preview · the gates are the statute
Outbound

AI tools you do not control

Copilot runs under your firm's Microsoft agreement. Until Microsoft commits to U.S.-only processing and the firm can show who reaches the data, Claremont's position is that client tax return information goes into Microsoft 365 Copilot only with each client's consent. The Clean Room is for everything else.

Who these are for

Accounting and tax practices, law firms, and any professional services firm holding client records that cannot afford exposure. The deadline generator and the notice references are built for federal tax practice; the checks and the instrument apply to any firm carrying a written security obligation.

How they work

Everything runs inside your browser and no account is required. Close the tab and the data is gone, except the Clean Room’s firm dictionary, which stays in this browser until you remove it. One more exception: the AI Readiness Check has a send button, and using it posts your firm name, your name, your email and the report to us. Nothing is sent unless you press it. If one of these surfaces a gap you would rather not have found, that is worth a conversation.

General reference only. Not tax, legal, or accounting advice. Deadlines and procedures change, so verify against current IRS guidance and your own professional judgment before relying on any output.

16 CFR 314.4(j) · 30 days to notify the FTC of a notification event of 500 or more consumers16 CFR 314.6 · below 5,000 consumers, 314.4(b)(1), (d)(2), (h) and (i) do not apply; every other paragraph does16 CFR 314.2(m) · encrypted customer information with the key intact is not a notification event16 CFR 314.4(c)(5) · multi-factor authentication for any individual accessing any information system, unless an equivalent control is approved in writing16 CFR 314.4(c)(6) · secure disposal within two years of last use, unless a named exception applies16 CFR 314.4(f) · service providers bound by contract to maintain safeguards, and reassessed26 U.S.C. §6713 · $250 per disclosure of return information, $10,000 per calendar year26 CFR §301.7216-2(d)(1), (d)(3) · return information goes without consent only to a preparer located in the United States; a contractor’s employee abroad who only views it puts the disclosure outside the United States