Security & trust

Where We Actually Stand on Security.

Written for the firm owner deciding whether to hand FirmLync client SSNs and financial data. This is not a compliance certification. For questions this page doesn't answer, email us and we'll answer directly rather than pointing at this page.

Where we are as a company

FirmLync is a new product. We don't have a long customer track record, a SOC 2 report, or a dedicated security team, and we want to be upfront about that rather than imply otherwise. What we do have: every control below is real and already live, not a roadmap item.

Access controls

Two-factor authentication is mandatory for every firm-staff account, not optional, since a password alone can't reach client data. Every firm's data is isolated by row-level security policies enforced in the database itself, not just application code. One firm can't query another firm's records, and a client portal login can only ever see that one client's own record. A log of sensitive actions taken with elevated access, including payments, autopay changes, and credentials used to send on a firm's behalf, is kept and viewable by the firm owner at any time in Settings.

Encryption, stated precisely

Data is encrypted at rest and in transit, using our database provider's (Supabase) standard infrastructure-level encryption. This is not end-to-end encryption. Standard encryption at rest protects against someone stealing a disk, not against the application itself reading data it needs to function. In practical terms, FirmLync's own operators can technically access stored data the same way any SaaS vendor's operators can. We don't claim otherwise, and any vendor who tells you their staff categorically cannot see your data, without describing actual client-side or zero-knowledge encryption, isn't being precise either.

E-signature

Signing requires a one-time code emailed at the moment of signing, an explicit consent checkbox, a hash of the signed document, and an auto-generated audit-trail PDF for every signature, beyond just typing a name while logged into the portal. This covers engagement letters, consent forms, fee agreements, and other standard business documents under typical U.S. e-signature law (ESIGN/UETA).

It does not cover IRS Form 8878/8879 (e-file signature authorization). The IRS requires identity verification (KBA) for remote signing of those specific forms, which requires a paid third-party identity verification vendor we don't currently integrate. Firms use FirmLync for everything else and handle 8879 by wet signature, in person, or with a separate KBA-capable tool for that one form.

Regulatory posture

Tax and accounting firms handling client financial data are generally subject to the FTC Safeguards Rule and, for paid preparers, an IRS-required Written Information Security Plan (WISP), not SOC 2, which is a voluntary market standard rather than a legal requirement for this industry. FirmLync is built with the Safeguards Rule's technical expectations in mind, including mandatory MFA, encryption, and access logging, but your firm's own WISP and compliance obligations are yours to maintain. We're a tool your firm uses, not a substitute for your firm's own compliance program. Talk to your own counsel about what applies to you.

Who else touches your data

Supabase (database, authentication, file storage) is the only subprocessor every firm's data passes through by default. Stripe (payments) is used only for firms that connect it. Twilio (SMS follow-ups) and Anthropic (AI-drafted follow-ups) are both on our roadmap and not live yet — email follow-ups are live today at no separate cost. We'll update this page as each ships. QuickBooks, Xero, and SmartVault are used only if you connect them. See our Privacy Policy for the full list.

Legal terms

Our Terms of Service and Privacy Policy are drafted to be substantively accurate, but haven't yet had a full review by outside counsel. We'll update this page when they have. If your firm needs a signed Data Processing Agreement or has specific contractual requirements, email us before you sign up and we'll work through it directly.