For Tax Firms

AI for your firm. Client files never leave the building.

Correspondence drafts, assessments condensed to their decisive points, the endless chase for missing documents, a firm knowledge base that answers instead of interrupting a colleague. That is the writing and searching work that currently ties up the people you cannot hire more of. It is also work that sits squarely inside professional secrecy under § 203 StGB — which is precisely why a client matter does not belong in a consumer chat window.

Architecture chosen by data risk§ 203 StGB as the frameWorks beside your existing systemsNo client data in the first call
The Situation

Deadlines press. Staff are scarce. And confidentiality rules out the shortcut.

Few professions combine this much text work with this strict a duty of confidentiality. Deadlines do not move, qualified people are hard to find, and every assessment, every email, every set of annual accounts contains material that is protected.

So the obvious shortcut — paste it into whatever tool is open — is not a grey area. It is a professional risk, and it is being taken quietly in a lot of firms right now precisely because nobody has offered a defensible alternative.

The answer is not to sit out AI while other firms get faster. It is to decide, task by task, what may run where.

Where It Helps

Where AI can take work off a firm like yours

Not every office needs all of these. Which ones are worth building depends on your workflows, your systems and what the hours actually cost you.

Client correspondence

Reply drafts, reminders and accompanying letters pre-written in the firm's tone. The professional reads, adjusts and sends.

Assessments and contracts, summarised

Long assessments, audit reports and contracts condensed to the decisive points before the file is opened properly.

Document requests and chasers

Missing items identified per client, request lists and follow-up letters drafted — instead of the perpetual hunt by individual email.

The firm knowledge base

Working instructions, model cases and internal notes, searchable and answering. New staff find in seconds what otherwise costs a colleague an interruption.

Pre-meeting dossiers

A briefing before each client meeting: current position, open points, deadlines, assembled from your own filing with the source shown.

What it does not do

Tax assessment, structuring advice, signatures. The reserved tasks stay with the professional; the AI takes the preparatory work, never the responsibility.

Architecture

The architecture follows the data risk, not a slogan.

Three routes are normally on the table, and the right one is decided per task rather than per company.

Systems you already run

If tools already cleared by your organisation can do the job, using what you have is usually the shortest route and the easiest to defend.

An EU-hosted service, contractually secured

For work that does not touch confidential material, a European service under a proper processing agreement is often the proportionate answer.

Running on your own machines

Where genuinely confidential material is processed, keeping the system inside the building can be the more sensible option. It is a possible answer, not automatically the right one.

What we will not do

  • Put confidential material into unvetted consumer tools
  • Automate a decision that belongs to a professional
  • Let anything reach a client without a defined human release
  • Promise an integration before the interface has been checked

How the decision gets made

  • Which data class each task actually touches
  • What your existing contracts and access rights already allow
  • What your systems can genuinely export or connect
  • Who maintains it once it is running
  • Whether the measurable benefit justifies the effort at all
How We Start

A check first. Not a project on faith.

Nothing gets built before the numbers are on the table. The first step is short, deliberately bounded, and useful even if you stop there.

01 · The check

One to two weeks. Your workflows mapped, the real effort quantified, the data classes sorted, your systems examined for what they actually allow — ending in a prioritised list and a plan for the first thing worth doing. The report is yours to keep.

02 · The first build

One use case taken to production against acceptance criteria agreed in advance, measured against the baseline from the check, and handed over with the training to run it.

03 · Running it

Keeping it current and monitored once it is live, with a periodic review of whether it is still earning its place — and the training record the EU AI Act expects of anyone whose staff use AI.

Scope, timing and a fixed price are agreed in writing before any work begins.

Fit

Who this is for

An honest filter costs both of us less than a wasted first meeting.

This fits if you recognise

  • A firm where correspondence and document chasing eat qualified hours
  • Deadline seasons that break the team rather than stretch it
  • Knowledge that lives in a few heads and leaves when they do
  • People already using AI tools privately with no firm rule about what may go in
  • A willingness to decide task by task rather than adopt or ban wholesale

This is not for you if

  • You want automated tax assessment or structuring advice — those are reserved tasks and stay that way
  • Nobody in the firm can own the topic
  • Your systems are so closed that nothing can be exported without a vendor project
  • You want a seal saying you are compliant rather than a defensible decision
Straight Answers

The questions that come up first

Do client data have to go into the cloud?

No. Much of the useful work involves no client-identifying material at all. Where it does, the check establishes what is defensible before anything is set up, with professional secrecy as the frame rather than an afterthought.

Does it work with our existing systems?

It is designed to work beside them, not replace them. Which exports or interfaces are genuinely available is something the check verifies rather than assumes.

What about the professional-secrecy obligation?

It applies in addition to data-protection duties, and a processing agreement does not substitute for it. Any external party involved has to be bound accordingly. That is a contract question we work through, not a technical one we design around.

Who is responsible for what the AI drafts?

The professional, exactly as with any preparatory work. Nothing is configured to send or file on its own; every draft waits for a human release.

How is the business case calculated?

From your own hours in the affected workflows, set against the expected effort of the solution. If a use case does not carry itself, that goes in the report.

Twenty minutes, and no client files.

Bring a rough sense of where the hours go — correspondence, document chasing, summarising, onboarding new staff. That is enough to say whether there is anything here worth building.

Request a call

Free and without obligation · direct with the founder