Data Security & Privacy
Where your data goes, and who can reach it
Written for two readers: the CFO deciding whether to send the general ledger, and the IT reviewer who has to sign off on it.
The Short Version
Your files stay in one controlled place.
Version 2.0 · September 2026
Client documents live in a restricted Google Drive folder. When analysis runs, only the files needed for that task are moved into a working folder permissioned to exactly two identities—Douglas, and a dedicated AI connector account. Output returns to that same folder. Working copies are deleted when the engagement ends.
There is no public link, no unprotected email attachment, and no sprawl of copies across personal devices. If your security team wants to interrogate that, we welcome the call.
The Process
How an engagement handles your data
-
01
Your files arrive in a restricted folder
Client documents are placed in a Google Drive folder that only Douglas Dillard can access. No other client, contractor, or third party has visibility into it.
-
02
Only what is needed moves to the working folder
As each piece of analysis begins, the specific files required are moved into a working folder. Documents not needed for the task at hand never enter the processing environment.
-
03
The working folder is scoped to two identities
That folder is permissioned to exactly two: Douglas, and the AI connector operating under a dedicated Bullseye Strategies account — separate from the email address used for client correspondence.
-
04
Analysis runs and output returns to the same folder
The deliverable is written back into the same permissioned folder. Your data does not travel to a third location, and no copy is left on a personal device.
-
05
Files are removed when the engagement ends
Working files are deleted on completion. Final deliverables remain wherever you have asked us to keep them — your environment, or the Bullseye-managed one.
Controls
What is actually in place
Stated plainly, so your reviewer can map each line to their own control framework.
Encryption at rest and in transit
Files remain in Google Drive, which encrypts data at rest and enforces TLS in transit. Nothing is emailed as an unprotected attachment.
Full-disk encryption
BitLocker is enabled on the workstation used for client work, so a lost or stolen device does not expose client financials.
Multi-factor authentication
MFA is enforced on every account with access to client data, including the separate account the AI connector runs under.
Separation of identity
The AI environment authenticates as admin@bullseyestrategies.net — not the address used for client email — so connector access is isolated from day-to-day correspondence.
Least-privilege folder scoping
Connector access is granted per folder, not across the whole Drive. Files outside the working folder are not reachable.
Deletion on completion
Working copies are removed at the end of an engagement rather than accumulating indefinitely.
The AI Platform
Model training and retention
Bullseye Strategies uses Claude, built by Anthropic, under an Anthropic Team plan—a commercial agreement, not a consumer subscription. Under those terms, client data processed during engagements is not used to train or improve any model. Model-improvement training is contractually excluded rather than switched off by preference, so it cannot be re-enabled by changing a setting.
Anthropic publishes these terms directly, and the distinction matters: consumer plans and commercial plans are governed by different agreements. Your security team is welcome to verify ours against the sources below, and we will provide the plan documentation on request.
Secure Delivery
Where your results end up
Option A
Your existing secure storage
If you already run ShareFile, SharePoint, Box, or OneDrive for Business, deliverables are exported into your environment. You keep ownership, audit trail, and permission management.
Option B
Bullseye-managed Google Workspace
For clients without enterprise document storage, we provision a dedicated environment: MFA enforced, a folder per client, link sharing disabled, and access logging on.
Verification
Don't take our word for it
Third-party certifications belong to the vendors that hold them and can change. Rather than reprint a list that may drift out of date, we link to the sources your security team can check directly.
We welcome security review
If your IT, compliance, or internal audit team needs to assess our data handling before an engagement begins, we will join a call and answer questions directly. That conversation is easier before a contract than after one.
Contact Us About Data Security