Security
Your clients trust you with their tax returns. Here is how Firmdesk protects them, in plain words, including what we haven't done yet.
Where your data is
- The app, its database and your documents are on servers in Beauharnois, Québec, run by OVHcloud.
- Each firm's data is kept apart from every other firm's. A page only ever looks inside the workspace you entered.
- Documents are never sent by email. Your clients open them in the portal, after signing in.
- Backup copies are kept with Cloudflare and may be stored outside Canada. When your portal has an address of its own, the connection to it goes through Cloudflare's network, which may carry it outside Canada without keeping it. Emails are delivered through a provider in the United States. All three are described in the privacy policy.
Signing in
- Two steps for your team. After the password, a code from an authenticator app. Owners and admins always use it, and you can require it of everyone.
- Two steps for your clients. After the password, a code emailed to them.
- Passwords need 12 characters or more, and can't be one that is known from a data breach. They are kept as one-way hashes: nobody can read them.
- Guessing is stopped. After 5 wrong passwords for an account, sign-ins for it wait 15 minutes.
- Sessions end on their own after 12 hours without activity for your team, 2 for clients. Anyone can see where they are signed in and sign out everywhere else.
Who sees what
- You decide each person's access. Every member sees the hours logged on each client's page, not what they're worth. Billing, what time is worth and everyone's timesheets are for partners, managers, owners and admins.
- A client's contact sees only what you shared with that client.
- An activity log records who signed in, who opened or shared which document, and what changed, for 12 months. Owners and admins can read it and download it.
- Our own staff look at a firm's data only to keep the service running, when you ask for help, or to import the files you send us for your move (each time shows in your activity log).
Encryption
- In transit: every connection is encrypted (TLS), and browsers are told to refuse anything else.
- In the browser: pages tell the browser to run only Firmdesk's own code, and to refuse to show Firmdesk inside another site.
- Backups: encrypted at rest by the storage provider.
- On the server: the database and documents are on a disk in a data centre with controlled access. They are not yet encrypted a second time by the app. It is on our list, and this page will say so when it is done.
Backups
- The database is backed up every night, and so are the documents. Copies are kept away from the server.
- Backups are kept up to 30 days. What you delete disappears from them within that time.
- We'll practise restoring from a backup every quarter; the first drill is due before the first pilot firm joins.
Files
- Only the kinds of files firms exchange can be uploaded. Programs, web pages and scripts are refused, judged by what the file is, not only its name. There's no virus scanning.
- Documents are handed out only by the app, after checking who is asking. They have no public address.
Your data stays yours
- Export everything at any time: a spreadsheet for every kind of record, and every document.
- Delete a client, or the whole workspace, yourself. A deleted workspace is gone after 30 days.
If something goes wrong
- The service is checked every three minutes from outside. Its state is public: status.firmdesk.ca.
- If your data is lost or seen by someone who shouldn't have, we tell you without delay: what happened, what was affected and what we are doing.
Report a problem
Found a weakness? Write to admin@firmdesk.ca. We answer within two business days, and we don't take action against people who report in good faith.
Filling in a security questionnaire for your own clients or your insurer? Ask us: we'll send our written answers.