Written to be checked, not skimmed

How FirmHello holds your clients' documents

A professional firm holds a concentration of personal information that would be valuable to somebody. This page sets out what we do about that, in enough detail to be checked rather than taken on trust.

Encrypted in transit and at rest
TLS 1.3 on every connection and AES-256 encryption for stored documents, with keys managed separately from the data they protect.
Access is per client, not per firm
A client can only ever load their own space. Staff access is granted per client, so a junior can be given three files and nothing else.
No documents in email
Notifications tell a client that something is waiting and link them to the portal. The material itself never leaves it as an attachment.
Complete audit trail
Views, uploads, downloads, approvals and permission changes are all recorded with actor, time and IP, and the log is exportable.
Retention you control
Set how long documents live per client or per matter, and hold or purge on request, so the portal matches the retention policy you already have.
Hosted in your region
Choose United States, Canada, the EU or the United Kingdom, and your firm's data stays in that region.

The specifics

If you are the person who has to sign this off, these are the answers you need.

Documents are never email attachments

This is the largest single risk reduction available to a firm, and it is a property of how the product is built rather than a setting somebody can get wrong. Notifications tell a client that something is waiting and link them to the portal. The document is never attached, never passes through a mail server, and never sits in a sent folder indefinitely.

A forwarded notification therefore grants the recipient nothing, because access belongs to the client record rather than to the link.

Encryption

TLS 1.3 on every connection, with earlier protocol versions refused rather than deprecated, and HSTS enforced. Documents are encrypted at rest with AES-256 and the key material is held in a separate managed service, so access to the storage layer alone does not yield readable documents. Database backups are encrypted with separate credentials.

Access control

A client session is bound to a single client record; there is no feature in the product that would render another client's material to a client. Staff access is granted per client rather than per firm, so a seasonal preparer holds exactly the engagements they are working on and nothing else. On the Firm plan, staff authenticate through your identity provider, which means access ends when an account is disabled.

Any individual item can be marked to require a one-time code before it can be opened or uploaded against, which is worth doing for identification documents and defeats the case where a client's own mailbox has been compromised.

Logging

Every view, upload, download, approval and permission change is recorded with actor, timestamp and IP address. Views are logged, not only uploads and downloads, because the question a client actually asks is who opened their file. The log is exportable per client or per engagement by you, without contacting us.

Retention and residency

Retention periods are set per client or per engagement type, purges are performed on schedule and the purge itself is logged so you can evidence that it happened. A full export is available before deletion at any time.

Your firm's data is held in the region you choose at setup — the United States, Canada, the European Union or the United Kingdom — and is not migrated out of it. Our sub-processor list is published and we will tell you before it changes.

Answering your firm's security questionnaire

If your firm runs a vendor review, send us the questionnaire and we will complete it rather than pointing you at a marketing page. Ask us for the sub-processor list, the data flow, the retention defaults and the incident process, and you will get specifics.

If something you need is not in place yet, we will say so in the response instead of writing around it. That is a faster answer for both of us than finding out in week six of a procurement process.

Reporting something to us

If you believe you have found a vulnerability, email security@firmhello.com. We will acknowledge within one business day, we will not threaten anybody who reports in good faith, and we will tell you when it is fixed.

Questions we have not answered here

Email security@firmhello.com and a person who built it will answer. If you are evaluating us for a firm, say so and we will go through your checklist properly.

No card and no sales call. If you would rather tell us about your firm first, use the longer form.