Security
You are being asked to put client bank statements through a supplier you have not heard of before. That is a reasonable thing to be careful about. This page is written so your security review is a link rather than an afternoon. There is also a completed short-form security questionnaire (PDF) you can hand straight to whoever asks.
Last reviewed September 2026. If something here is not enough for your review, ask and we will answer in writing.
Where your data is held
All application data and all client files are held in the European Union. The database and the application servers run in the EU, and file storage is an EU region of an S3-compatible object store. Backups stay in the EU. Nothing is replicated outside the EU or the UK.
A UK-region option is available on request for firms that need it.
Encryption
- In transit
- TLS 1.2 or better on every connection, including the client checklist page, the firm application, our inbound email endpoint and every call to a sub-processor. HTTP requests are redirected to HTTPS. HSTS is set.
- At rest
- AES-256 on database volumes, file storage and backups.
- Integration credentials
- Tokens for your Google Drive or OneDrive are encrypted with an application key held outside the database and are decrypted only inside the job that uploads your files. They are never written to a log, never shown in the interface and never returned by any interface we expose.
Access control
- Your firm's data is isolated by firm at the application layer and again by PostgreSQL row-level security, so a query that forgets the firm filter returns nothing rather than someone else's records. This is covered by an automated test that attempts to read another firm's data through every route and must pass before any deployment.
- Two-factor authentication is mandatory for firm owners and available to all staff. Sessions time out after eight hours. Login is rate limited.
- Client checklist links carry a 128-bit random token, expire 30 days after the request completes, are bound to the first device that opens them, and require an emailed code if opened on a new device. A PIN can be required as well.
- Staff access on our side is least-privilege and individually named. There are no shared accounts. Access to production is logged.
What we do with files that arrive
Every inbound file is scanned for malware before it is stored, its type is checked against its contents rather than its extension, images are re-encoded, and size limits are enforced. Files are never executed and are served back only through short-lived signed links. Raw inbound email is kept for 30 days so a failed delivery can be reprocessed, then purged.
Retention and deletion
- You set the retention period for your firm. When it expires, files are deleted on schedule.
- You can export everything your firm holds, as JSON plus the files in a zip, at any time and without asking us.
- If you close your account, data is recoverable for 30 days and then permanently deleted, with the deletion recorded in the audit log and a certificate available on request.
- Backups age out on their own schedule, which is 35 days.
Audit trail
Every change to a request and every access to a file is written to an append-only audit log with the actor, the action and the time. You can export your firm's log. We cannot alter it after the fact.
Sub-processors
These are the third parties that can process data on our behalf. We will give 30 days' notice before adding one.
| Sub-processor | Purpose | Data it can see | Region |
|---|---|---|---|
| Hosting provider (EU) | Application servers, database, backups | All application data | EU |
| Object storage provider (EU) | Client files | Files your clients send | EU |
| Transactional email provider | Sending requests and reminders, receiving replies | Message content and attachments in transit | EU or UK |
| Error tracking | Application errors | Stack traces only. File contents and message bodies are excluded by configuration. | EU |
| Stripe | Subscription billing | Your firm's billing contact and payment details. No client data. | EU and US, under its own terms |
| SMS provider (from Phase 2, not yet live) | Reminders by text in your firm's name | Reminder text and mobile numbers | EU or UK |
Named providers are confirmed at contract. If your firm needs the specific legal entities and their data processing terms before signing, ask and we will send the list.
Artificial intelligence
There is no AI in the product today. When document classification arrives it will be opt-in per firm, no customer data will be used to train any model, prompts will be logged without file content, and account numbers will be redacted before anything is sent to a model. This paragraph will be updated before that ships, not after.
If something goes wrong
- We aim to acknowledge a suspected incident within four working hours and to contain it before diagnosing it.
- If your data is affected we will tell you what happened, what we changed and what to watch, within 72 hours of becoming aware, in line with UK GDPR breach notification.
- You will get one honest message per incident rather than silence followed by a summary.
- Report anything you find to us directly. We do not use legal threats against people who report security problems in good faith.
Assurance
- UK GDPR and EU GDPR: a data processing agreement is available at /dpa and can be signed before you send us anything.
- Cyber Essentials: application in progress. The certificate will be published here when it is issued rather than described before it exists.
- Penetration test: an external review of link handling and firm isolation is planned before the full launch.
- ISO 27001: not held. We would rather say so than imply otherwise.
Contact
Security questions and incident reports go to the founder directly and are answered by a person, not a form. Ask through the front page and mark it security.