Ricerca

Your financials and IP, handled like they matter

An R&D study touches the material a company guards hardest: payroll, ledgers, product roadmaps, engineering activity, and trade secrets. So the interesting question isn’t whether we say we take security seriously - it’s which controls are actually running while your study is built.

Below is what we do, stated plainly, plus what we don’t claim.

A dim server room aisle with illuminated network cabling running through equipment racks
Study data lives on managed cloud infrastructure, reached through read-only connectors and access-restricted workflows.Photo by Taylor Vick on Unsplash
What’s different about an R&D study

Three controls built for tax data on AI infrastructure

Generic security pages stop at encryption. These are the controls that exist because the workload is a tax study processed with AI.

§7216 confidentiality, enforced in code

Taxpayer-identifying data is redacted automatically before anything reaches an AI model. The confidentiality rules that govern tax-return information are implemented as a processing step, not as a paragraph in a policy binder.

Enterprise AI endpoints only

In production, AI calls route exclusively through enterprise Azure AI Foundry endpoints - not consumer chat products. Your data is never used to train public or third-party models.

Read-only, minimal connectors

Accounting and payroll connections are read-only: we can read what a study needs and cannot write anything back. Engineering connectors collect activity metadata only - never your source code.

These are platform behaviors, not aspirations - the same ones described on the platform page, where you can see how data moves from a connector to a finished substantiation file.

Safeguards

Concrete controls - not slogans

The protections below describe how your data is actually handled while a study is in flight - and, in the same table, the two certifications we do not hold.

Security controls and certification status
Control What it means for your data Status
Encrypted in transit and at restData moves over TLS and is encrypted at rest in storage. That applies to uploads, connector pulls, and every deliverable we issue.Running today
Least-privilege accessAccess is granted per engagement, on a need-to-know basis, behind strong authentication - not handed out platform-wide by default.Running today
Data minimizationWe ask for what the study actually requires and nothing speculative. Fewer fields collected is fewer fields exposed.Running today
Your data isn’t training dataYour confidential information is never used to train public or third-party AI models. It is used to perform your study, and for nothing else.Running today
Audit loggingSensitive actions are logged, so access and activity across the platform leave a reviewable record rather than a memory.Running today
Controlled document handlingPayroll files, ledgers, and technical documents are stored, transmitted, and processed inside access-restricted workflows.Running today
Retention and deletionWe follow a defined retention and deletion policy and can remove your data on a documented schedule when the engagement ends.Running today
Segregated environmentsEach client’s data is logically segregated, and access to production is restricted and monitored.Running today
SOC 2 reportWe hold no SOC 2 report today, and we will not claim an attestation we do not have.Not held
ISO certificationWe hold no ISO certification today.Not held
Formal SOC 2 examinationOn our roadmap. We describe it as a commitment rather than an accomplishment.Roadmap
Status reflects what is running on the platform today. Certification rows are stated in full under “Where we are - stated honestly” below.

AI makes us faster. It doesn’t get your data for free.

AI accelerates intake, document parsing, computation, and first-draft narratives. It runs under governance: taxpayer-identifying data is redacted before processing, calls go through enterprise Azure AI Foundry endpoints in production, usage is metered and logged, and nothing you give us is used to train public or third-party models.

Qualification decisions, QRE amounts, and the final numbers are made by people - then reviewed and finalized by our R&D experts before the study is issued. The AI never gets the last word, which is both a quality control and a security one.

See how we use AI

Compliance posture

Where we are - stated honestly

Because an R&D study is built from tax-return information, we design our safeguards around the expectations that apply to tax professionals handling that data - the safeguarding guidance in IRS Publication 4557, the information-security program requirements of the FTC Safeguards Rule, and the confidentiality rules of IRC §7216, which we implement as an automated redaction step rather than a policy reminder.

We maintain written information-security practices covering access, retention, and incident response, and we will walk a prospective client’s security team through them on request.

On certifications: we hold no SOC 2 report and no ISO certification today. A formal SOC 2 examination is on our roadmap, and we describe it as a commitment rather than an accomplishment - we won’t claim an attestation we don’t have. We also won’t tell you a system is “100% secure” or “unhackable”; nobody can. What we offer is specific controls, described accurately, and the willingness to be questioned about them.

Have a security questionnaire, a vendor review, or contractual requirements? Email [email protected] - we typically reply within one business day.

The five questions security teams ask us

Where is our data hosted, and who else touches it?
Ricerca is a United States company and the study platform runs on managed cloud infrastructure; AI processing routes through enterprise Azure AI Foundry endpoints. The third-party processors involved in running the site and delivering messages to us are named individually in our Privacy Policy - we would rather list them than describe them vaguely.
Who at Ricerca can see our financials and source data?
The people working your engagement, and the R&D experts who review and finalize it. Access is least-privilege and per-engagement rather than platform-wide, authentication is enforced, and sensitive actions are logged. Nobody browses client data out of curiosity, and the log would show it if they tried.
Is our data used to train AI models?
No. Your confidential information is never used to train public or third-party AI models. AI is used to accelerate intake, parsing, computation, and first-draft narratives on your study only - through enterprise endpoints, with taxpayer-identifying data redacted before processing.
Can we have our data deleted when the engagement ends?
Yes - email us and we will work through it. We operate a defined retention and deletion policy; some records are retained where the engagement agreement or applicable law requires it, and our Privacy Policy sets out the detail.
Will you complete our security questionnaire or review an NDA?
Send it over. We will walk your security or IT team through the controls on this page, complete a standard vendor questionnaire, and review your NDA or data-processing terms as part of scoping the engagement. What we will not do is check a box for a certification we do not hold.

More detail lives in the Privacy Policy and the Terms of Service. If you want to see the safeguards in the context of the work they protect, read how a study works or what Audit Protection covers.

Questions about how we protect your data?

We’ll walk your team through the controls, answer your security questionnaire, and review your NDA or data-processing terms - before you share a single payroll file.

[email protected] We typically reply within one business day.
Get your free credit estimate

We typically reply within one business day.