FirmaryJoin the waitlist

Security

Security and data handling

Firm separation
Each firm’s data is kept separate from every other firm’s. Every read and write is authorized on the server against the firm’s boundary, and our test suites check isolation between firms.
Sign-in
Owners and admins must always use multi-factor authentication. Sign-in uses OpenID Connect, with authenticator apps, passkeys, and backup codes as second factors. Sign-in and invitation endpoints are rate-limited, and the limiter fails closed.
Encryption and hosting
Firmary never handles payment card data; Stripe processes and records charges. Each firm’s integration credentials are encrypted at rest with AES-256-GCM.
File uploads
Files that clients or staff upload are scanned for viruses before anyone can download them. Infected files are quarantined and never delivered.
Activity records
Firmary keeps a record of who did what, and when. State-changing actions are written to an append-only audit log scoped to your firm.
Independent assessments
Firmary has not yet completed a third-party security audit or a SOC 2 examination. We run internal security reviews and automated secret scanning, and SOC 2 readiness work has started.
← Back to firmary.app