Tenant isolation
Each engagement's data is separated by row-level security in the database. Access is checked on the server, not only in the browser.
Let’s talk ↗Trust Center
A plain account of what we do, what we don't and what we are still building. If a control is not in place, it does not appear on this page.
Each engagement's data is separated by row-level security in the database. Access is checked on the server, not only in the browser.
Firm Force staff use MFA. Only the partners assigned to your engagement can see your data.
Downloads and exports are disabled per engagement until we confirm the recipient, and every export is logged.
Sign-ins, data changes, administrative actions and exports are written to append-only logs.
Every production change is reviewed for security and logged with a change record.
We act as custodians, you may request a full export or deletion at any time, and your data is never sold or shared between clients.
Questions
No, database-level isolation separates every engagement.
Yes, and we will walk your IT team through our controls before you share anything.
Only the partners assigned to your engagement.
Tell us and we will remove it, though it is better to strip that data before upload because no automated screen catches everything.
Not yet, but our controls are designed around the Trust Services Criteria and we share the control mapping under NDA.