Security overview

Security boundaries should be testable.

The product implements application controls for tenant separation, role-restricted actions, governed records and external sharing. The operating organization remains responsible for secure configuration, infrastructure and monitoring.

Identity and access

Accounts are invitation-only. Firm and workspace membership are checked on protected actions, sensitive administration is permission-gated, and password reset or account deactivation invalidates existing sessions.

Application protection

State-changing browser requests use CSRF protection. Session cookies are HTTP-only and SameSite-protected, with secure cookies required in production. Controlled document HTML is sanitized before display.

External sharing

Auditor links use high-entropy tokens stored as hashes. Shared document views are limited to approved or published records and sanitize controlled content.

Records and evidence

Governed versions, review decisions and audit events preserve decision history. Production upload processing requires malware scanning when deployed with the documented configuration.

Deployment evidence matters.

Encryption keys, TLS, backups, malware-scanner health, logging, patching and infrastructure access depend on the operator's deployment. Ask the operator to demonstrate these controls for the environment you will use.

Report a security issue

Use the security contact path or contact the organization that gave you access. Do not include live secrets or personal data in the first message.

A machine-readable disclosure contact is available at /.well-known/security.txt.