Written for the person who has to sign this off

What makes a secure client portal for accountants actually secure

Every portal claims to be secure. The word is doing very little work. Here is the specific set of properties that matter when the documents are tax records, and how FirmHello implements each.

Free for 14 days, no credit card. Your portal carries your firm's name from the first client you add.

Lindhurst & Vale's portal, as their client sees it.

An accounting practice holds a concentration of personal financial information that would be attractive to anybody. Identification documents, income, bank details, everything needed for identity theft, for several hundred households, in one place.

That makes the portal a serious decision rather than a convenience purchase. This page sets out what we do, in enough detail to be checked, and is honest about where we are in the process of being independently verified.

The properties that matter

In roughly the order a reviewer should work through them, with what FirmHello does for each.

Documents never travel as email attachments

This is the largest single risk reduction available to a practice, and it is architectural rather than a setting. FirmHello notifications tell a client that something is waiting and link them to the portal. The document itself is never attached, never sent to a mail server, and never sits in a sent folder indefinitely.

  • Notifications contain no client data beyond the firm's name and a link
  • Uploads go directly to encrypted storage, not through a mailbox
  • A forwarded notification grants the recipient nothing

Encryption in transit and at rest

TLS 1.3 for every connection, with older protocol versions refused rather than merely deprecated. Documents are encrypted at rest with AES-256, and the key material is managed separately from the stored data so that access to the storage layer alone yields nothing usable.

  • TLS 1.3, HSTS enforced, no mixed content
  • AES-256 at rest with keys held in a separate managed service
  • Database backups encrypted with separate credentials

Access is scoped per client, in both directions

A client can only ever load their own space; there is no construct in the product for a client-facing view that spans clients. Staff access is granted per client rather than per firm, so a seasonal preparer can be given the twelve returns they are working on and nothing else.

  • Client sessions are bound to a single client record
  • Staff grants are per client, revocable individually
  • Single sign-on on the Group plan, so leavers lose access with their account

Optional step-up verification on sensitive items

Identification documents deserve a higher bar than a bank statement. Any item can be marked to require a one-time code sent separately before it can be opened or uploaded against, which defeats the case where a client's mailbox is itself compromised.

  • Per-item one-time code requirement
  • Optional passwords for clients who want one
  • Session expiry and device-level session revocation

A log that answers the question you will actually be asked

The question is never "was there a log". It is "who opened my tax return, and when". Every view, upload, download, approval and permission change is recorded with actor, timestamp and IP address, and the log is exportable per client or per engagement without contacting us.

  • Views recorded, not only uploads and downloads
  • Permission changes recorded with who made them
  • Self-service export, no support ticket required

Retention that matches the policy you already have

A practice has a retention policy. A portal that keeps everything forever quietly replaces it with a different one. Retention is set per client or per engagement, and a purge is performed and recorded so you can evidence that it happened.

  • Retention configurable per client and per engagement type
  • Purge on request, with the purge itself logged
  • Full export before deletion, on demand

Where the data lives

Choose United States, Canada, the European Union or the United Kingdom at setup, and your firm's documents stay in that region. Sub-processors are listed publicly and we will tell you before the list changes.

  • Region chosen at setup and not silently migrated
  • Sub-processor list published and versioned
  • Notice before any change to the list

What to put in your vendor questionnaire

If your firm runs a vendor review, send the questionnaire and we will complete it rather than pointing you back at this page. The questions worth insisting on are the ones a marketing page tends to answer with an adjective.

Ask any vendor, including us, to answer these in writing. An answer you cannot quote back later is not an answer.

  • What exactly does the audit log record, and can you export it yourself?
  • Where is the data held, and can it be moved without telling you?
  • Who are the sub-processors, and are you told before that list changes?
  • How is access revoked when a staff member leaves?
  • What does a data export look like, and can you run one unaided?

The mechanics underneath

Every feature

Audit trail

Views, downloads, approvals and permission changes with actor, time and IP, exportable by you.

Your brand, your domain

Requests arrive from your firm at your domain, which is the practical defense against clients being unable to tell you from a phishing attempt.

Client vault

Encrypted at rest with separately managed keys, retention set per client, full export on demand.

Roles and per-client access

Per-client staff grants, roles, and single sign-on on the Group plan, so access ends when an account is disabled.

Request lists

Per-item one-time codes for identification and other high-sensitivity items.

Approvals on the record

Approved documents stored with the full approval record rather than emailed back and forth.

Client documents are the most sensitive thing a firm holds

So the portal is built to hold them properly: encrypted, access granted one client at a time, and every action recorded. Nothing travels as an email attachment.

How FirmHello is built
Encrypted in transit and at rest
TLS 1.3 on every connection and AES-256 encryption for stored documents, with keys managed separately from the data they protect.
Access is per client, not per firm
A client can only ever load their own space. Staff access is granted per client, so a junior can be given three files and nothing else.
No documents in email
Notifications tell a client that something is waiting and link them to the portal. The material itself never leaves it as an attachment.
Complete audit trail
Views, uploads, downloads, approvals and permission changes are all recorded with actor, time and IP, and the log is exportable.
Retention you control
Set how long documents live per client or per matter, and hold or purge on request, so the portal matches the retention policy you already have.
Hosted in your region
Choose United States, Canada, the EU or the United Kingdom, and your firm's data stays in that region.

Questions a reviewer should ask

Will you complete our vendor security questionnaire?

Yes. Send it to security@firmhello.com and a person who works on the product will complete it. Where something is not in place, the response will say so rather than writing around the question.

Who are your sub-processors?

The list is published and versioned, and we notify you before it changes. Ask and we will send you the current version along with the data flow it belongs to.

How are documents encrypted?

TLS 1.3 in transit, AES-256 at rest, with key material held in a separate managed service so that access to storage alone is not access to documents.

Can one client ever see another client's documents?

A client session is bound to a single client record, so there is no product feature that would render another client's material. Staff access is separately granted per client.

What happens if a client's email account is compromised?

Notifications contain no documents, so an attacker in the mailbox sees only that a firm is waiting on something. Items marked sensitive additionally require a one-time code sent through a separate channel.

Can we get the audit trail for an insurer or a regulator?

Yes, and without asking us. Export the log per client or per engagement yourself, at any time.

Where is our data stored?

In the region you choose at setup — United States, Canada, the European Union or the United Kingdom — and it is not migrated out of it.

Ready when you are

If this is the level of detail you were looking for, the trial is free for 14 days.

No card and no sales call. If you would rather tell us about your firm first, use the longer form.