Trust center
Built for confidential engagement files
CPA firms entrust client workpapers to GAASFlow. This hub summarizes what is in place today, what remains on the maturity roadmap, and where to find legal and security documents.
Security controls
HTTPS in transit, bcrypt password hashing, multi-tenant firm isolation, role-based access, TOTP MFA with QR setup, login history, rate limiting, security headers and CSP baselines, client portal separation, and optional firm-required MFA.
Security details →Data processing
Published Data Processing Addendum, privacy policy, AI terms, and acceptable use policy. Card data is handled by our payment processor—not stored on application servers.
Read the DPA →Subprocessors
Infrastructure, database, payments, email, and optional AI providers used to operate the service.
View subprocessors →Service status
Live availability checks for platform health. Contact support for incidents.
System status →Responsible disclosure
How to report a security vulnerability in good faith.
Disclosure policy →Product transparency
Current product boundaries, a public roadmap, and dated product updates.
Roadmap →In place today
Controls you can evaluate now
- Encryption in transit (HTTPS / TLS)
- Provider-managed encryption at rest for production database volumes
- Multi-tenant firm_id isolation on application queries
- Role-based access (Owner, Partner, Manager, Staff, Reviewer)
- TOTP MFA with authenticator QR (opt-in or firm-required)
- Login history for security review
- Email verification on signup
- Password policy and time-limited reset tokens
- Rate limits on auth, portal, AI, and support chat
- Security headers including CSP, HSTS, frame denial
- Client PBC portal isolated from internal workpapers
- Activity and sign-off accountability on engagements
- Dated synthetic production logical restore drill completed August 6, 2026
- Daily operational database and error monitoring with immutable evidence
Maturity roadmap
Planned control maturity
SOC 2 Type I → Type II
Control documentation and independent report readiness for firms that require it. Not completed today—published honestly.
Independent penetration testing summary
Third-party testing summaries for enterprise questionnaires as the program matures.
SAML / SSO
Enterprise single sign-on for larger firms (Firm plan priority).
Provider point-in-time restore exercise and published RTO/RPO
The logical restore drill is complete. A separately evidenced provider PITR exercise and contractual recovery targets remain on the maturity roadmap.
Security questionnaire pack
Self-serve starting set for vendor security reviews. We do not claim SOC 2 or SSO today — those are on the published roadmap.
- Trust center (this page)
- Security controls detail
- Data Processing Addendum
- Subprocessors
- Live system status
- Responsible disclosure
- Privacy policy
- Terms of service
Support@GAASFlow.com