Skip to main content
This article describes capabilities at a general level. For contractual specifics, certifications, and current status, refer to your agreement with Adopt and the security documentation Adopt provides.

What Adopt is built to support

Because Adopt is aimed at regulated finance and accounting teams, it’s designed around the controls those teams need:
  • Client data isolation — strict per-client boundaries (see Isolation and multi-tenancy).
  • Human review of outputs — an always-on approval gate with recorded, attributable approvals.
  • Access controls — role- and scope-based permissions, granted least-privilege.
  • On-premises and data-residency options — for clients who can’t send data to hosted services, deployment options exist to keep data in place. Confirm availability for your plan.
  • Model flexibility — options including bring-your-own-key and open-weight / self-hosted inference for cost or sovereignty reasons.

Deletion and retention

Retention is handled per engagement (process), so a client’s records for one process can follow a different retention rule than another. Where regulated retention periods apply — workpaper retention requirements, for example — set retention to match. Confirm the exact retention controls available in your plan.

Your responsibilities

  • Scope access tightly and review it periodically.
  • Keep reviewers assigned, so the HITL gate is never a bottleneck that tempts a workaround.
  • Follow your own firm’s and regulators’ requirements for what may be processed and retained.

Next steps

  1. Isolation and multi-tenancy
  2. Roles and permissions
  3. Human-in-the-loop review