Your clients' trust is our product.
CPA firms operate under strict confidentiality obligations. RCKN was designed from day one to earn that trust — not ask you to compromise it.
Postgres rows and knowledge-graph records carry a workspace identifier. Supported application queries enforce that scope, with row-level security protecting Postgres access paths where configured.
The provider consent screen shows the permissions RCKN requests. Mail connections include read, send, and mailbox-management access because RCKN can sync messages and perform actions you explicitly choose.
RCKN does not use customer email content to train its own models. Model APIs receive the context required for a requested feature under the configured provider terms; a current subprocessor list is available on request.
One deletion operation covers uploaded draft files, knowledge-graph nodes, Postgres records, and OAuth connections. It reports per-store outcomes so a partial failure is visible and can be retried; no fixed completion time is promised.
Supported sensitive actions, including draft and mailbox mutations, write attributed audit events. Hash chaining makes later changes detectable; it does not imply that every read is logged.
OAuth credentials are stored server-side with application-layer authenticated encryption. Transport, storage, key-management, and regional controls are documented for the active deployment instead of being represented by an unverified blanket claim.
Enterprise prospects can request the current security questionnaire, architecture summary, subprocessor list, and the controls that apply to their proposed deployment.