The company
Tidy Account AS was founded in 2010 with a single stated objective: grow from zero to NOK 10 million in revenue within ten years. The firm hit that trajectory and has since been recognized as a Gazelle company five times, expanding to 20 employees across two offices in Trondheim and Rissa.
Growth of that kind puts pressure on an accounting firm in a specific place. More clients mean more sensitive documents in motion: payroll data, tax filings, financial statements, identity information. More staff means more people handling that material, at widely varying levels of experience. For a firm operating under GDPR and Norwegian accounting regulation, every additional client and every additional hire is also additional exposure.
Managing Director Raymond Bergesen points to the firm’s technology choices, Verji’s secure communication solution in particular, as what made it possible to scale without that exposure compounding.
The challenge
Tidy Account’s problem was not that it lacked security measures. It was that its security measures only worked in one direction.
Like most accounting firms, Tidy Account sent confidential documents as encrypted PDFs, distributing the access codes separately. The outbound leg was protected. The inbound leg was not. Clients would open the encrypted document, read it, and then reply with their questions, and their bank details, their personal identification numbers, their financial data, over ordinary, unencrypted email.
This created three compounding problems:
A compliance gap the firm could not close. Tidy Account could control how it sent information. It could not control how clients sent information back. Every reply was a potential GDPR incident originating outside the firm’s control but landing inside its systems.
A workflow that consumed billable time. Encrypting each document, generating codes, distributing them through a second channel, and fielding the inevitable “I can’t open this” calls added administrative overhead to routine client correspondence.
No visibility into junior work. Client correspondence lived in individual inboxes. A senior partner had no practical way to observe how a junior colleague was handling a client conversation until something had already gone wrong, or to step in with specialist knowledge at the moment it was needed.
The wider risk picture reinforced the urgency. Deloitte research indicates that over 90% of fraud and data attacks can be traced back to email.
The solution
Tidy Account moved its client communication onto Verji’s encrypted platform, replacing the encrypted-PDF workflow with end-to-end encrypted, two-way messaging and file sharing.
The critical difference was that protection now covered both directions. Clients no longer had a mechanism for replying insecurely, because the reply happened inside the encrypted channel. The compliance gap closed not through policy or client training, but through the design of the tool.
Adoption was the second consideration, and in an accounting context it is the one that usually decides whether a security rollout survives contact with reality. Secure platforms that clients find difficult get abandoned in favor of email within weeks. Both Tidy Account’s team and its clients found Verji immediately intuitive, closer in feel to a consumer messaging app than to enterprise security software, while meeting the requirements of a regulated firm.
How Tidy Account uses Verji
Verji now handles internal and external communication, file sharing, and day-to-day collaboration across the firm.
The Rooms functionality has produced the most significant change to how the firm works. Client conversations happen in shared rooms rather than individual inboxes, which means senior partners can follow several client relationships simultaneously and intervene precisely when specialist expertise is required.
The practical effect is consistency. A 16-person firm inevitably has a spread of experience levels, and clients do not adjust their expectations to match. Rooms allows senior capability to be applied across many more conversations than any partner could personally own — so service quality stays even regardless of who is holding the relationship day to day. This was structurally impossible with email threads, where oversight meant either being copied on everything or finding out after the fact.
The results
Zero security or GDPR breaches. Across three years and all client communication, Tidy Account has recorded no security incidents and no GDPR breaches.
Over 60% reduction in reliance on email. The majority of client and internal correspondence has moved off email entirely, shrinking the attack surface that accounts for the overwhelming share of fraud attempts against professional services firms.
Encrypted-PDF workflow eliminated. The encrypt-generate-distribute-support cycle no longer exists. The administrative time it consumed has returned to client work.
Senior oversight at scale. Rooms gives partners visibility across concurrent client conversations, protecting service quality as the firm continues to hire.
Growth sustained. Tidy Account has maintained Gazelle status through the period, demonstrating that the security posture has not come at the cost of commercial momentum.
Why it matters
Tidy Account’s experience addresses the assumption that regulated firms face a genuine trade-off between operating efficiently and operating securely. The firm did not accept slower workflows in exchange for compliance. It got faster workflows and closed its largest compliance gap in the same move.
That is the case Verji is built to make for accounting and audit firms, law firms, and regulated SMEs across Europe, a market Verji is now expanding into with strategic investment and partnership from TGC Capital Partners.
About Verji Tech AS
Verji Tech AS is a Norwegian technology company specializing in encrypted communication solutions for regulated industries. Our platform provides end-to-end encrypted messaging, file sharing, voice and video calling, BankID signing, and intelligent workflows for businesses that require GDPR compliance and rigorous information security.