Operating Policies

The product commitments behind FinButler: privacy, secure sharing, clear permissions, responsible AI extensibility, and straightforward communication with customers and firms.

Core commitments

Privacy and control

Users and firms should understand how their data is used, and they should be able to control how financial context is shared.

Security by default

Authentication, storage, and collaboration features should be designed so trust is built into the system, not bolted on later.

Permission-aware collaboration

Clients, firms, and internal teams should only see the workspace context and reports appropriate to their role.

Responsible AI and MCP

AI workflows and hosted MCP should extend product value while respecting the same trust model users see in the UI.

How these policies show up in the product

Workspace boundaries

Internal work can stay private, firm work can live in dedicated accountant-facing flows, and client-facing collaboration can stay intentionally scoped.

Role-based access

Permissions should be visible, understandable, and aligned with the real responsibilities of a team, firm, or client stakeholder.

Report delivery with context

Shared reports and follow-up requests should stay connected to the workspace path that produced them.

MCP as extension, not bypass

Hosted MCP should make FinButler more useful in external tools without creating a second, less accountable path around product controls.

Related documents

These operating policies sit alongside our public legal and trust documentation. For the latest details, use the pages below.