Skip to main content

Legal

Data Handling & Security Policy

How Kearney & Partners protects nonpublic personal, financial, and organizational information across engagements.

Kearney & Partners LLC · Effective July 2026 · Reviewed annually

  • Written Information Security Program aligned with the FTC Safeguards Rule
  • US-based SharePoint storage with encryption, MFA, and least-privilege access
  • Documented incident response with client notification without unreasonable delay

Effective date:

KEARNEY & PARTNERS LLC

1640 Powers Ferry Rd SE, Building 11, Suite 200
Marietta, GA 30067

(470) 645-2666

Kearney & Partners LLC (“Kearney & Partners”) handles nonpublic personal, financial, and organizational information in the course of its audit process management, ongoing accounting & bookkeeping, financial operations transformation, and Strategic Finance & Operational Advisory services. This one-page policy summarizes how we protect that information and forms part of every signed engagement letter's information-security terms. It should be read together with our Privacy Policy and Terms of Service.

1. Framework

Kearney & Partners maintains a Written Information Security Program (WISP) covering risk assessment, administrative safeguards, technical safeguards, physical safeguards, and incident response. The WISP is designed to be consistent with the FTC Safeguards Rule (16 CFR Part 314) and applicable state data-security requirements, and is reviewed at least annually and after any material change in business practices or risk profile.

2. Data Storage & Segregation

Client data is stored in Kearney & Partners' US-based Microsoft SharePoint environment, provisioned under Microsoft 365 with tenant-level access controls. Each client is provisioned to a segregated site with permissions scoped to that engagement. Client data is not stored on personal devices, personal cloud accounts, or unmanaged local drives. Portable media is not used to move client data.

3. Encryption

Client data is encrypted at rest using Microsoft 365 platform-managed encryption (AES-256) and encrypted in transit using TLS 1.2 or higher for all transfers, including email exchange, portal uploads, and SharePoint synchronization. Files exchanged outside the SharePoint environment are transmitted through encrypted channels only.

4. Access Controls

Access to client data is governed by least-privilege principles. Multi-factor authentication (MFA) is required for all Kearney & Partners personnel, contractors, and offshore production personnel accessing client systems, email, or SharePoint. Access is provisioned by role at engagement onboarding and reviewed on a recurring basis; access is revoked promptly upon personnel departure or scope change.

5. Personnel & Offshore Production

All Kearney & Partners personnel, US-based contractors, and offshore production personnel with data access sign written non-disclosure and confidentiality agreements before onboarding, complete annual data-security and confidentiality training, and work under Kearney & Partners' direct supervision. Offshore production personnel access client data only through Kearney & Partners' controlled SharePoint environment and are subject to the same MFA, encryption, and access controls as US-based staff. Professional judgments and sign-off on the firm's work are made by the licensed partner responsible for it. Client deliverables are issued under that partner's review and approval.

6. Vendor Oversight

Kearney & Partners maintains a vendor inventory covering any third parties with access to client data (including Microsoft 365, e-signature, and payment-processing providers). Vendors are selected based on published security posture (SOC 2 Type II reports or equivalent, where available), and vendor access is reviewed at least annually.

7. Record Retention & Disposal

Engagement files, workpapers, and related records are retained for the longer of (a) applicable state CPA licensing requirements or (b) any document-retention period the client is itself subject to under federal award or Uniform Guidance requirements (see 2 CFR 200.334), where applicable. At disposal, digital records are permanently deleted from SharePoint and any backup copies through documented procedures; physical records, if any, are shredded.

8. Incident Response

Kearney & Partners maintains a documented incident response procedure covering detection, containment, investigation, notification, and remediation. If Kearney & Partners becomes aware of a security incident reasonably believed to involve unauthorized access to a client's nonpublic personal or financial information, Kearney & Partners will notify the affected client without unreasonable delay and cooperate with the client's own notification and regulatory obligations. Notification will include, at minimum, the nature of the incident, the categories of information involved (to the extent known), the containment steps taken, and the remediation plan.

9. Client Responsibilities

Clients are responsible for using secure methods when transmitting sensitive information to Kearney & Partners, maintaining the security of their own systems, portals, and credentials, and promptly notifying Kearney & Partners of any suspected compromise on the client's side that may affect information shared with us. No electronic transmission, cloud platform, or storage system can be guaranteed completely secure.

10. Limitations

This policy summarizes Kearney & Partners' current data-handling practices and does not create rights or obligations beyond those set out in a signed engagement letter. In the event of any conflict between this policy and a signed engagement letter for a specific engagement, the engagement letter controls for that engagement.

11. Contact & Updates

For general privacy questions, see our Privacy Policy or contact hello@kearneypartners.com. For security-incident notifications, WISP requests under NDA, or questions specific to this policy, contact the engagement partner or security@kearneypartners.com directly. This policy is reviewed at least annually and is updated as practices, technology, or regulations change; the “Effective” date above reflects the most recent update.

Kearney & Partners LLC · 1640 Powers Ferry Rd SE, Building 11, Suite 200, Marietta, GA 30067 · (470) 645-2666 · kearneypartners.com/data-handling