Security at FirmSync

We understand that law firms handle sensitive client data. Security isn't an afterthought—it's built into everything we do.

Encryption

All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption.

Secure Infrastructure

Hosted on trusted cloud infrastructure from industry-leading providers.

Access Controls

Secure authentication, role-based access controls, and activity logging.

Security Monitoring

Continuous monitoring for security anomalies and prompt incident response.

Data Protection

Encryption in Transit: All data transmitted between your browser and our servers is protected using TLS 1.3 with strong cipher suites.
Encryption at Rest: All stored data, including invoices and billing information, is encrypted using AES-256 encryption.
Secure File Storage: Uploaded invoices are stored in encrypted, access-controlled cloud storage with automatic versioning and backup.
Data Isolation: Each customer's data is logically isolated using secure multi-tenant architecture.

Access Management

Authentication: Secure password requirements with bcrypt hashing. OAuth 2.0 integration for Clio and other practice management systems.
Session Management: Secure session tokens with automatic expiration and rotation. Sessions are invalidated on password change or logout.
Audit Logging: Comprehensive logging of all access and changes to your data, available for review upon request.
Least Privilege: Internal access to production systems is strictly limited and monitored.

Infrastructure Security

Cloud Infrastructure: Hosted on trusted cloud platforms that maintain their own security certifications and compliance programs.
Network Security: HTTPS-only access, secure API endpoints, and protection against common web vulnerabilities.
Dependency Management: Regular updates and security patches for all software dependencies.
Backup & Recovery: Regular automated backups to protect against data loss.

AI & Data Processing

AI Provider Security: We use Anthropic's Claude API, which maintains enterprise-grade security and does not use your data for model training.
No Data Retention by AI: Invoice content processed by AI services is not retained beyond the immediate processing session.
Data Minimization: We only send the minimum necessary data to AI services for processing.
Customer Data Isolation: Your data is never used to train AI models or shared with other customers.

Privacy Practices

Privacy by Design

Data minimization and user control built into our architecture

Implemented

CCPA Awareness

Designed with California Consumer Privacy Act principles in mind

Committed

Data Portability

Export your data anytime in standard formats

Implemented

Incident Response

We are committed to quickly detecting, containing, and resolving any security issues. Our approach includes:

Monitoring: Application logging and error tracking to detect anomalies.
Prompt Response: Quick investigation and resolution of reported security concerns.
Customer Notification: We will notify affected customers promptly if a security incident impacts their data.
Continuous Improvement: We learn from any issues to strengthen our security posture.

Report a Security Vulnerability

We take security seriously and appreciate responsible disclosure. If you discover a security vulnerability in FirmSync, please report it to us immediately.

Report Vulnerability

Have questions about our security practices? Contact us