Xero
xero.com
Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.
- No clear commitment that your data will not train their models
- Data retention window not stated
- No independent assurance evidenced
+1 more
See Before you sign, with what to ask for ↓
Scanned Aug 25, 2026 · Public evidence · Point-in-time
Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.
Before you sign
Why it matters: The public sources scanned do not clearly state that customer prompts, files, and outputs are excluded from training or fine-tuning of first- or third-party models.
What to ask for: Get a no-training clause covering first- and third-party models into the DPA/order form.
“No, JAX chat doesn’t use your data to train the LLMs it uses.”
“As part of the commercial arrangements with these providers, we ensure that any data we send them remains secure and isn’t retained to train their models.”
Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.
What to ask for: Get retention windows, in days, in writing.
“They process the data you enter, which may include personal data, but this data is not retained and isn't used to train the LLMs.”
“We'll retain your personal data for as long as we've a relationship with you and for a period of time afterwards where we have an ongoing business or legal need to keep it.”
Why it matters: No SOC 2 Type II, ISO/IEC 42001, or registry-verified certification covering the AI product was found in the public sources scanned.
What to ask for: Request a SOC 2 Type II or ISO/IEC 42001 report and confirm its scope covers the AI product.
Why it matters: The public sources scanned do not state where customer data is processed or offer a residency option.
What to ask for: Pin processing regions per data classification in the contract.
Buyer questionsanswered only from the public evidence scanned — click a row for the answer
!Will they train on your data?Ask the vendor
Xero states JAX chat does not use customer data to train the LLMs it uses.
Requires written confirmation — see Before you sign ↓
“No, JAX chat doesn’t use your data to train the LLMs it uses.”
“As part of the commercial arrangements with these providers, we ensure that any data we send them remains secure and isn’t retained to train their models.”
!How long do they keep your data?Ask the vendor
Data entered into JAX, which may include personal data, is stated not to be retained by the LLM providers.
Requires written confirmation — see Before you sign ↓
“They process the data you enter, which may include personal data, but this data is not retained and isn't used to train the LLMs.”
“We'll retain your personal data for as long as we've a relationship with you and for a period of time afterwards where we have an ongoing business or legal need to keep it.”
✓Who else can access your data?Clear
Xero names its LLM providers — AWS, Microsoft Azure, GCP and OpenAI — and states they are disclosed and vetted to the same degree as all other subprocessors.
“For large language models (LLMs), we use third-party providers like AWS, Microsoft Azure, GCP, OpenAI who are disclosed and vetted to the same degree as all other sub-processors we use.”
“Xero and Anthropic are partnering to bring Claude's advanced reasoning into Xero, and your live financial data into Claude.ai, so trusted intelligence isn't locked into one platform.”
“Third parties We use a few different third-party subprocessors to help us provide our services to you. These subprocessors process data that you input into the services, which may include personal data. Here we’ve set out some info on who the subprocessors are, what”
!Where is your data processed?Ask the vendor
Not found in the public sources scanned — ask the vendor directly.
!What happens in a security incident?Ask the vendor
Not found in the public sources scanned — ask the vendor directly.
Confirm in writing: Ask the vendor to state this in writing before signing.
Key findingsclick a row for the evidence
✓Named LLM providers with no-training and no-retention commitmentsStrong
Xero names its LLM providers (AWS, Microsoft Azure, GCP, OpenAI), commits that JAX data is neither retained by them nor used to train their models, and states this is contractually backed and subprocessor-vetted.
This answers the three questions buyers ask first — who processes the data, is it retained, is it trained on — directly and in one place, which is rare at this level of specificity.
“For large language models (LLMs), we use third-party providers like AWS, Microsoft Azure, GCP, OpenAI who are disclosed and vetted to the same degree as all other sub-processors we use.”
“No, JAX chat doesn’t use your data to train the LLMs it uses.”
“They process the data you enter, which may include personal data, but this data is not retained and isn't used to train the LLMs.”
“As part of the commercial arrangements with these providers, we ensure that any data we send them remains secure and isn’t retained to train their models.”
!Anthropic/Claude integration announced under a forward-looking disclaimerGap
The Anthropic partnership adds Claude to the model supply chain and moves live financial data into Claude.ai, but the page's own disclaimer says future features may differ and should not be relied on for purchase decisions.
A buyer assessing today's supply chain should know whether the Claude path is live, and whether the same no-training/no-retention terms extend to it.
Question for vendor: Is the Claude/Claude.ai integration live for customers, and do the same non-retention and non-training terms apply to Anthropic as to the other LLM providers?
“Xero and Anthropic are partnering to bring Claude's advanced reasoning into Xero, and your live financial data into Claude.ai, so trusted intelligence isn't locked into one platform.”
!No independent AI assurance evidence in the fetched setGap
The fetched pages carry no certification or external assessment claims — no ISO 27001/42001, SOC 2 or equivalent appears in the captured public AI and trust content.
The strong first-party commitments currently rest on Xero's own statements; independent assurance would let a buyer rely on them without further verification.
Question for vendor: Which independent certifications or assurance reports does Xero hold, and are JAX and its AI pipeline within their scope?
“No, JAX chat doesn’t use your data to train the LLMs it uses.”
“As part of the commercial arrangements with these providers, we ensure that any data we send them remains secure and isn’t retained to train their models.”
✓Permission-model parity and invoke-only operationStrong
JAX inherits Xero's existing role-based permissions, runs only when a user invokes it, and access can be managed through the roles organisations already administer.
AI features that inherit the existing authorisation model avoid the shadow-access risks of bolt-on assistants.
“JAX chat follows the same access rules as the rest of Xero, so users can only see data they’re already permitted to access.”
“We're transparent about when we use AI and we endeavour to explain the 'why' behind its answers.”
?Microsoft observed but not named in public materialsObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a undefined, which the vendor's public trust materials do not name.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Microsoft appears to be involved as a undefined — can you confirm and disclose this relationship?
“For large language models (LLMs), we use third-party providers like AWS, Microsoft Azure, GCP, OpenAI who are disclosed and vetted to the same degree as all other sub-processors we use.”
“Xero and Anthropic are partnering to bring Claude's advanced reasoning into Xero, and your live financial data into Claude.ai, so trusted intelligence isn't locked into one platform.”
?Atlassian observed but not named in public materialsObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a undefined, which the vendor's public trust materials do not name.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Atlassian appears to be involved as a undefined — can you confirm and disclose this relationship?
“For large language models (LLMs), we use third-party providers like AWS, Microsoft Azure, GCP, OpenAI who are disclosed and vetted to the same degree as all other sub-processors we use.”
“Xero and Anthropic are partnering to bring Claude's advanced reasoning into Xero, and your live financial data into Claude.ai, so trusted intelligence isn't locked into one platform.”
?Stripe observed but not named in public materialsObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a undefined, which the vendor's public trust materials do not name.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Stripe appears to be involved as a undefined — can you confirm and disclose this relationship?
“For large language models (LLMs), we use third-party providers like AWS, Microsoft Azure, GCP, OpenAI who are disclosed and vetted to the same degree as all other sub-processors we use.”
“Xero and Anthropic are partnering to bring Claude's advanced reasoning into Xero, and your live financial data into Claude.ai, so trusted intelligence isn't locked into one platform.”
✓Conversational-AI providers named on the subprocessor listStrong
Xero's subprocessor list names Anthropic and OpenAI as conversational-AI providers, alongside AWS, Microsoft Azure and Google Cloud Platform for infrastructure.
An accounting platform routing customer conversations to two external model providers is a supply-chain fact a buyer needs before enabling AI features on financial data.
Question for vendor: Confirm which conversational-AI provider receives your data, whether that content is used for training, and how a change of provider is notified.
“infrastructure service provider, United States Anthropic, Conversational artificial intelligence services, United States Avalara, United States, Sales tax look-up (United States), United States CloudFactory, Data extraction and processing, United Kingdom Confluent, Cloud infrastructure service”
“Third parties We use a few different third-party subprocessors to help us provide our services to you. These subprocessors process data that you input into the services, which may include personal data. Here we’ve set out some info on who the subprocessors are, what”
?Technical dependency observed: MicrosoftObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“For large language models (LLMs), we use third-party providers like AWS, Microsoft Azure, GCP, OpenAI who are disclosed and vetted to the same degree as all other sub-processors we use.”
“Xero and Anthropic are partnering to bring Claude's advanced reasoning into Xero, and your live financial data into Claude.ai, so trusted intelligence isn't locked into one platform.”
“infrastructure service provider, United States Anthropic, Conversational artificial intelligence services, United States Avalara, United States, Sales tax look-up (United States), United States CloudFactory, Data extraction and processing, United Kingdom Confluent, Cloud infrastructure service”
“Third parties We use a few different third-party subprocessors to help us provide our services to you. These subprocessors process data that you input into the services, which may include personal data. Here we’ve set out some info on who the subprocessors are, what”
?Technical dependency observed: AtlassianObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“For large language models (LLMs), we use third-party providers like AWS, Microsoft Azure, GCP, OpenAI who are disclosed and vetted to the same degree as all other sub-processors we use.”
“Xero and Anthropic are partnering to bring Claude's advanced reasoning into Xero, and your live financial data into Claude.ai, so trusted intelligence isn't locked into one platform.”
“infrastructure service provider, United States Anthropic, Conversational artificial intelligence services, United States Avalara, United States, Sales tax look-up (United States), United States CloudFactory, Data extraction and processing, United Kingdom Confluent, Cloud infrastructure service”
“Third parties We use a few different third-party subprocessors to help us provide our services to you. These subprocessors process data that you input into the services, which may include personal data. Here we’ve set out some info on who the subprocessors are, what”
?Technical dependency observed: StripeObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“For large language models (LLMs), we use third-party providers like AWS, Microsoft Azure, GCP, OpenAI who are disclosed and vetted to the same degree as all other sub-processors we use.”
“Xero and Anthropic are partnering to bring Claude's advanced reasoning into Xero, and your live financial data into Claude.ai, so trusted intelligence isn't locked into one platform.”
“infrastructure service provider, United States Anthropic, Conversational artificial intelligence services, United States Avalara, United States, Sales tax look-up (United States), United States CloudFactory, Data extraction and processing, United Kingdom Confluent, Cloud infrastructure service”
“Third parties We use a few different third-party subprocessors to help us provide our services to you. These subprocessors process data that you input into the services, which may include personal data. Here we’ve set out some info on who the subprocessors are, what”
Assurance dimensionsweighted components of one score — not eight separate ratings
Organisation & AI governance15% of the score60
Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.
Assessed against ISO 42001 · NIST AI RMF · AIUC-1
“JAX chat follows the same access rules as the rest of Xero, so users can only see data they’re already permitted to access.”
“We're transparent about when we use AI and we endeavour to explain the 'why' behind its answers.”
Governance & accountability: vendor-evidenced, not yet independently corroborated.
AI system15% of the score20
What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.
Assessed against ISO 42001 · NIST AI RMF
“You can think of JAX as a superagent, a master orchestrator that directs and coordinates multiple AI agents in the background to complete a task or a series of tasks.”
How AI features are evaluated before and after release — evals, red-teaming, monitoring.
Assessed against NIST GenAI · NIST AI RMF · ISO 42001
How changes to models and AI features are controlled and communicated — versioning, notice, rollback.
Assessed against ISO 27001 · ISO 42001
AI system description: vendor-evidenced, not yet independently corroborated.
Testing & evaluation: not publicly evidenced.
Change management: not publicly evidenced.
Model10% of the score75
Which model providers and versions process customer data, and how changes to them are disclosed.
Assessed against NIST GenAI · ISO 42001
“infrastructure service provider, United States Anthropic, Conversational artificial intelligence services, United States Avalara, United States, Sales tax look-up (United States), United States CloudFactory, Data extraction and processing, United Kingdom Confluent, Cloud infrastructure service”
“Third parties We use a few different third-party subprocessors to help us provide our services to you. These subprocessors process data that you input into the services, which may include personal data. Here we’ve set out some info on who the subprocessors are, what”
“For large language models (LLMs), we use third-party providers like AWS, Microsoft Azure, GCP, OpenAI who are disclosed and vetted to the same degree as all other sub-processors we use.”
“Xero and Anthropic are partnering to bring Claude's advanced reasoning into Xero, and your live financial data into Claude.ai, so trusted intelligence isn't locked into one platform.”
Customer data15% of the score60
Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.
Assessed against ISO 27018 · OAIC APPs · EU AI Act
“No, JAX chat doesn’t use your data to train the LLMs it uses.”
“They process the data you enter, which may include personal data, but this data is not retained and isn't used to train the LLMs.”
“We'll retain your personal data for as long as we've a relationship with you and for a period of time afterwards where we have an ongoing business or legal need to keep it.”
Customer data treatment: vendor-evidenced, not yet independently corroborated.
AI supply chain10% of the score75
The named chain of AI and infrastructure providers behind the product, and how it is disclosed.
Assessed against ISO 27001 · ISO 27017
“infrastructure service provider, United States Anthropic, Conversational artificial intelligence services, United States Avalara, United States, Sales tax look-up (United States), United States CloudFactory, Data extraction and processing, United Kingdom Confluent, Cloud infrastructure service”
“Third parties We use a few different third-party subprocessors to help us provide our services to you. These subprocessors process data that you input into the services, which may include personal data. Here we’ve set out some info on who the subprocessors are, what”
Security foundation15% of the score0
How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.
Assessed against ISO 27001 · NIST AI RMF
Vulnerability & incident handling: not publicly evidenced.
Independent assurance evidence10% of the score0
Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.
Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008
Independent assurance: not publicly evidenced.
Legal & contractual10% of the score40
The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.
Assessed against EU AI Act · OAIC APPs
“As part of the commercial arrangements with these providers, we ensure that any data we send them remains secure and isn’t retained to train their models.”
Not graded: Agent — not applicable to this scan.
What would strengthen assuranceeach figure is from today's score — resolving one changes the others
Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 40 → up to 70 with every identified gap resolved.
AI supply chainclick a node to focus it · drag to pan · zoom with the controls
View as list
What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0
This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.
Map your inherited responsibilitiesAssurance evidence: certifications 1 — registry checks and verification ladders, click to view
Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.
Sources 12 — click to view
Appendix: standards landscape 8 — click to view
Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.
Want to go further?
This scan assesses Xero at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.
Scan a specific product →This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.
