Trust & security
Designed for confidential engagement files
CPA firms entrust client workpapers to GAASFlow. Below is what is in place today, what is on the maturity roadmap, and how to request security documentation for evaluations.
Controls
In place today
Controls implemented in the application and production hosting stack.
Production traffic is served over HTTPS with modern TLS. Engagement data is not transmitted in the clear.
Passwords are hashed with bcrypt (cost factor 12). Sessions use industry-standard JWT cookies via NextAuth.
New accounts require at least 10 characters with letters and numbers. Reset tokens expire in one hour.
Application queries are scoped by firm_id so one firm cannot read another firm’s users, engagements, or documents.
Owner, Partner, Manager, Staff, and Reviewer roles. Firm settings and billing controls stay with leadership.
Signup, password reset, support chat, and client portal routes enforce request limits.
Invite tokens are unique, time-limited, and single-use. Seat limits reduce uncontrolled sprawl.
PBC share links expose prepared-by-client requests only — not internal workpapers, risk files, or review notes.
Production responses include HSTS, frame denial, nosniff, referrer policy, COOP/CORP, permissions policy, and Content-Security-Policy baselines.
Auth, support chat, AI assist, and portal routes apply per-IP / per-user rate limits to blunt abuse.
Engagement saves and key events are recorded so partners can see who last touched the file.
Card data is handled by our payment processor. Card numbers are not stored on GAASFlow application servers.
Print packages and partner summaries keep work product under firm control for export and permanent files.
TOTP authenticator MFA under Firm settings with a scannable QR code (no third-party QR service). Optional per user, or firm-wide require-MFA policy (owner-controlled). Login requires the code when MFA is enabled.
Recent sign-in attempts for known accounts include timestamp, result, source IP when supplied by the trusted deployment proxy, and browser agent under Firm settings for review by the user or authorized firm leadership.
New accounts receive a verification link (48-hour expiry). A banner prompts resend until the address is confirmed.
Client and server errors are rate-limited and stored for operator review (no session replay of engagement content). Optional Sentry / webhook paging when configured.
Production Postgres is hosted with provider-managed volume encryption (Neon / Vercel infrastructure). Application-level field encryption / custom KMS is not claimed.
Public /status page reports live database and integration configuration presence without exposing secrets.
Engagement documents use tenant-scoped private bytes, immutable versions, integrity hashes, plan quotas, server-side MIME/signature and archive safety validation, locks, and retention-hold enforcement. This screening is not represented as an independent antivirus service.
Firm owners can invalidate active member sessions. Server-side session versions and firm-required MFA are checked before firm data is authorized.
On August 6, 2026, a synthetic production tenant was backed up, deleted, restored, hash-verified, and cleaned up without touching customer data. This does not claim a provider point-in-time recovery test.
Daily database and error probes record immutable operational evidence and alert through configured email or webhook channels.
Security maturity roadmap
We publish roadmap items clearly rather than overstating certifications we have not yet completed. Larger firms evaluating GAASFlow can review published legal terms and the DPA while on trial.
Optional application-level encryption controls for firms that require them beyond provider volume encryption.
Control documentation and audit readiness are on the compliance roadmap for firms that require an independent report.
Enterprise single sign-on for larger firms is planned; priority for Firm plan customers.
Third-party testing summaries for enterprise evaluations as the program matures.
Numeric recovery commitments and a separately evidenced provider point-in-time branch restore remain to be completed.
Optional network and device restrictions for high-security firm policies.
For firm evaluations
Start a trial to evaluate tenancy isolation, access control, data ownership, and export in the product. Legal terms, DPA, AI data terms, and the customer security pack (subprocessors, encryption, backup posture) are published for review.
Related policies
Security contact: Support@GAASFlow.com