The trust argument is architectural.
Cert doesn't ask you to trust a vendor's cloud with your tax data — it runs inside the Microsoft tenant you already govern. This page is written to be forwarded to IT, security, and legal.
Where your data lives
One design decision does most of the security work: there is no Trojion cloud holding customer data.
Your tenant is the boundary
Cert deploys as a managed Power Platform solution into your existing Microsoft Dataverse environment. Your financial and tax data is stored, processed, and backed up inside your tenant — Trojion has no standing access to it.
You inherit Microsoft's controls
Because the runtime is your environment, your existing Entra ID authentication, conditional access, DLP policies, Purview auditing, encryption at rest, and Dataverse backup and residency settings all apply to Cert automatically.
Data residency follows your Dataverse region
Cert stores nothing outside your Dataverse environment, so your data stays in the Microsoft region your organisation has already chosen — EU, UK, US, or elsewhere.
Signed regulatory releases
OECD rates and thresholds ship as dated, versioned, ECDSA-signed parameter packs. Your environment verifies the signature before applying an update — rates cannot be silently altered.
Every data flow, stated plainly
Three surfaces, three different answers — none of them vague.
The Cert product
Nothing leaves your tenantRuns entirely in your Microsoft tenant. No customer financial or tax data is transmitted to, stored by, or accessible to Trojion.
Cert IQ (optional add-on)
Request-scoped, opt-inWhen enabled, request-scoped context only — for example, the account descriptions being mapped — transits Cert's authenticated Azure gateway to Anthropic's Claude model for the duration of the request. Nothing is retained by Trojion, and commercial API terms prohibit training on your data. Disable Cert IQ and this path does not exist.
This website (cert.tax)
Website onlyA static site on Cloudflare Pages. No cookies, no cross-site tracking, no AI. Forms are relayed to our inbox by Web3Forms; analytics, where enabled, is Cloudflare's cookieless measurement.
Integrity of the numbers
Security is also about whether a figure can be silently changed. In Cert, it can't.
Provenance on every figure
Every number traces back through the calculation to the source data that produced it, with the OECD reference cited on each line.
Server-enforced approval workflow
Draft → Reviewed → Approved → Filed is a state machine enforced server-side, not a convention. Sealed filings can only change through visible, attributed amendments.
Evidence Pack
A sealed, auditor-ready record per group, fiscal year, and scenario — inputs, rates, results, and who approved what, when.
Deterministic engine
The calculation engine is deterministic and versioned. The same inputs always produce the same outputs; AI never computes your figures.
Subprocessors
The complete list. Changes are notified to customers in advance.
| Provider | Scope | Applies to |
|---|---|---|
| Microsoft (your tenant) | Cert product runtime — Dataverse, Power Apps | All customers (under your own Microsoft agreement, not ours) |
| Microsoft Azure (Trojion) | Cert IQ gateway — authentication, scoping, rate control | Only with Cert IQ enabled |
| Anthropic, PBC | Claude model inference on request-scoped context | Only with Cert IQ enabled |
| Cloudflare, Inc. | Marketing website hosting, DNS, cookieless analytics | Website visitors only — never product data |
| Web3Forms | Website form relay to our inbox | Website form submissions only |
For your procurement file
Everything a purchase decision needs, available on request.
Put your security team on the demo call.
We'll walk through the architecture and the Cert IQ data flow with IT and legal in the room — that conversation is usually shorter than the questionnaire.