Trust & security

Designed for confidential engagement files

CPA firms entrust client workpapers to GAASFlow. Below is what is in place today, what is on the maturity roadmap, and how to request security documentation for evaluations.

Controls

In place today

Controls implemented in the application and production hosting stack.

Encryption in transit

Production traffic is served over HTTPS with modern TLS. Engagement data is not transmitted in the clear.

Password hashing

Passwords are hashed with bcrypt (cost factor 12). Sessions use industry-standard JWT cookies via NextAuth.

Password policy & reset

New accounts require at least 10 characters with letters and numbers. Reset tokens expire in one hour.

Multi-tenant isolation

Application queries are scoped by firm_id so one firm cannot read another firm’s users, engagements, or documents.

Role-based access

Owner, Partner, Manager, Staff, and Reviewer roles. Firm settings and billing controls stay with leadership.

Rate limiting

Signup, password reset, support chat, and client portal routes enforce request limits.

Invitation security

Invite tokens are unique, time-limited, and single-use. Seat limits reduce uncontrolled sprawl.

Client portal isolation

PBC share links expose prepared-by-client requests only — not internal workpapers, risk files, or review notes.

Security headers

Production responses include HSTS, frame denial, nosniff, referrer policy, COOP/CORP, permissions policy, and Content-Security-Policy baselines.

API rate limits

Auth, support chat, AI assist, and portal routes apply per-IP / per-user rate limits to blunt abuse.

Activity accountability

Engagement saves and key events are recorded so partners can see who last touched the file.

Payment processing

Card data is handled by our payment processor. Card numbers are not stored on GAASFlow application servers.

Data portability

Print packages and partner summaries keep work product under firm control for export and permanent files.

Multifactor authentication (MFA)

TOTP authenticator MFA under Firm settings with a scannable QR code (no third-party QR service). Optional per user, or firm-wide require-MFA policy (owner-controlled). Login requires the code when MFA is enabled.

Login history

Recent sign-in attempts for known accounts include timestamp, result, source IP when supplied by the trusted deployment proxy, and browser agent under Firm settings for review by the user or authorized firm leadership.

Email verification

New accounts receive a verification link (48-hour expiry). A banner prompts resend until the address is confirmed.

Application error capture

Client and server errors are rate-limited and stored for operator review (no session replay of engagement content). Optional Sentry / webhook paging when configured.

Encryption at rest (provider)

Production Postgres is hosted with provider-managed volume encryption (Neon / Vercel infrastructure). Application-level field encryption / custom KMS is not claimed.

Live status checks

Public /status page reports live database and integration configuration presence without exposing secrets.

Private document storage

Engagement documents use tenant-scoped private bytes, immutable versions, integrity hashes, plan quotas, server-side MIME/signature and archive safety validation, locks, and retention-hold enforcement. This screening is not represented as an independent antivirus service.

Session revocation

Firm owners can invalidate active member sessions. Server-side session versions and firm-required MFA are checked before firm data is authorized.

Dated logical restore drill

On August 6, 2026, a synthetic production tenant was backed up, deleted, restored, hash-verified, and cleaned up without touching customer data. This does not claim a provider point-in-time recovery test.

Operational monitoring

Daily database and error probes record immutable operational evidence and alert through configured email or webhook channels.

Security maturity roadmap

We publish roadmap items clearly rather than overstating certifications we have not yet completed. Larger firms evaluating GAASFlow can review published legal terms and the DPA while on trial.

Roadmap
Customer-managed keys / field-level encryption

Optional application-level encryption controls for firms that require them beyond provider volume encryption.

Roadmap
SOC 2 Type I → Type II

Control documentation and audit readiness are on the compliance roadmap for firms that require an independent report.

Roadmap
SAML / SSO

Enterprise single sign-on for larger firms is planned; priority for Firm plan customers.

Roadmap
Independent penetration testing summary

Third-party testing summaries for enterprise evaluations as the program matures.

Roadmap
Published RTO/RPO targets and provider restore exercise

Numeric recovery commitments and a separately evidenced provider point-in-time branch restore remain to be completed.

Roadmap
IP allowlisting & advanced session controls

Optional network and device restrictions for high-security firm policies.

For firm evaluations

Start a trial to evaluate tenancy isolation, access control, data ownership, and export in the product. Legal terms, DPA, AI data terms, and the customer security pack (subprocessors, encryption, backup posture) are published for review.

Related policies

Security contact: Support@GAASFlow.com