Let’s talk ↗

How we protect
your firm's data.

A plain account of what we do, what we don't and what we are still building. If a control is not in place, it does not appear on this page.

Tenant isolation

Each engagement's data is separated by row-level security in the database. Access is checked on the server, not only in the browser.

Access control

Firm Force staff use MFA. Only the partners assigned to your engagement can see your data.

Exports off by default

Downloads and exports are disabled per engagement until we confirm the recipient, and every export is logged.

Audit logging

Sign-ins, data changes, administrative actions and exports are written to append-only logs.

Change management

Every production change is reviewed for security and logged with a change record.

Your data is yours

We act as custodians, you may request a full export or deletion at any time, and your data is never sold or shared between clients.

What security
teams ask us.

Can other clients see our data?

+

No, database-level isolation separates every engagement.

Will you complete our security questionnaire?

+

Yes, and we will walk your IT team through our controls before you share anything.

Who at Firm Force sees our data?

+

Only the partners assigned to your engagement.

What if we upload a file with employee SSNs or salaries?

+

Tell us and we will remove it, though it is better to strip that data before upload because no automated screen catches everything.

Do you have a SOC 2 report?

+

Not yet, but our controls are designed around the Trust Services Criteria and we share the control mapping under NDA.