Trust center

Built for confidential engagement files

CPA firms entrust client workpapers to GAASFlow. This hub summarizes what is in place today, what remains on the maturity roadmap, and where to find legal and security documents.

In place today

Controls you can evaluate now

  • Encryption in transit (HTTPS / TLS)
  • Provider-managed encryption at rest for production database volumes
  • Multi-tenant firm_id isolation on application queries
  • Role-based access (Owner, Partner, Manager, Staff, Reviewer)
  • TOTP MFA with authenticator QR (opt-in or firm-required)
  • Login history for security review
  • Email verification on signup
  • Password policy and time-limited reset tokens
  • Rate limits on auth, portal, AI, and support chat
  • Security headers including CSP, HSTS, frame denial
  • Client PBC portal isolated from internal workpapers
  • Activity and sign-off accountability on engagements
  • Dated synthetic production logical restore drill completed August 6, 2026
  • Daily operational database and error monitoring with immutable evidence

Maturity roadmap

Planned control maturity

SOC 2 Type I → Type II

Control documentation and independent report readiness for firms that require it. Not completed today—published honestly.

Independent penetration testing summary

Third-party testing summaries for enterprise questionnaires as the program matures.

SAML / SSO

Enterprise single sign-on for larger firms (Firm plan priority).

Provider point-in-time restore exercise and published RTO/RPO

The logical restore drill is complete. A separately evidenced provider PITR exercise and contractual recovery targets remain on the maturity roadmap.

Security questionnaire pack

Self-serve starting set for vendor security reviews. We do not claim SOC 2 or SSO today — those are on the published roadmap.

Email questionnaire request

Support@GAASFlow.com