Security
CPA firms entrust engagement files to GAAS Flow. We design for isolation, least privilege, exportability, and partner-visible accountability — and we say so on the product, not only in a footer footnote.
Production traffic runs over HTTPS with modern TLS. Client engagement data is not sent in the clear.
Passwords are hashed with bcrypt (cost factor 12). Sessions use industry-standard JWT cookies via NextAuth — not shared firm passwords.
New accounts require at least 10 characters with letters and numbers. Password reset tokens expire in one hour.
Every database query is scoped by firm_id. Firms cannot read each other's users, engagements, or documents — by design.
Owner, Partner, Manager, Staff, and Reviewer roles. Billing and firm branding stay with leadership.
Signup, password reset, and client portal endpoints enforce request limits to reduce brute-force and abuse.
Invite tokens are unique, time-limited, and single-use. Seat limits stop uncontrolled user sprawl.
PBC share links expose only prepared-by-client requests — never internal workpapers, risk files, or review notes.
Production responses include HSTS, X-Frame-Options DENY, nosniff, strict referrer policy, and Content-Security-Policy baselines.
Engagement activity history records saves and key events so partners can see who last touched the file.
Card data never touches GAAS Flow servers. Stripe Checkout and webhooks handle subscriptions with signed events.
Professional print packages and partner summaries keep work product under firm control — not locked in a black box.
Formal assurance programs (including SOC 2) are on the growth roadmap. Need a security questionnaire for a pilot? Start a trial and contact support through your firm owner account — we take procurement seriously without multi-year implementation theater.
Start free trial