What makes a secure client portal for accountants actually secure
Every portal claims to be secure. The word is doing very little work. Here is the specific set of properties that matter when the documents are tax records, and how FirmHello implements each.
Free for 14 days, no credit card. Your portal carries your firm's name from the first client you add.
2024 return — identity and income
6 of 8 received1 item overdue — FirmHello is chasing
- Photo identification One-time code used
- Proof of address Received 4 Mar
- Income summary Received 4 Mar
- ! Investment statements Overdue
- Confirm bank details Reminder tomorrow
- Engagement letter Approved 18 Jan
Lindhurst & Vale's portal, as their client sees it.
An accounting practice holds a concentration of personal financial information that would be attractive to anybody. Identification documents, income, bank details, everything needed for identity theft, for several hundred households, in one place.
That makes the portal a serious decision rather than a convenience purchase. This page sets out what we do, in enough detail to be checked, and is honest about where we are in the process of being independently verified.
The properties that matter
In roughly the order a reviewer should work through them, with what FirmHello does for each.
Documents never travel as email attachments
This is the largest single risk reduction available to a practice, and it is architectural rather than a setting. FirmHello notifications tell a client that something is waiting and link them to the portal. The document itself is never attached, never sent to a mail server, and never sits in a sent folder indefinitely.
- Notifications contain no client data beyond the firm's name and a link
- Uploads go directly to encrypted storage, not through a mailbox
- A forwarded notification grants the recipient nothing
Encryption in transit and at rest
TLS 1.3 for every connection, with older protocol versions refused rather than merely deprecated. Documents are encrypted at rest with AES-256, and the key material is managed separately from the stored data so that access to the storage layer alone yields nothing usable.
- TLS 1.3, HSTS enforced, no mixed content
- AES-256 at rest with keys held in a separate managed service
- Database backups encrypted with separate credentials
Access is scoped per client, in both directions
A client can only ever load their own space; there is no construct in the product for a client-facing view that spans clients. Staff access is granted per client rather than per firm, so a seasonal preparer can be given the twelve returns they are working on and nothing else.
- Client sessions are bound to a single client record
- Staff grants are per client, revocable individually
- Single sign-on on the Group plan, so leavers lose access with their account
Optional step-up verification on sensitive items
Identification documents deserve a higher bar than a bank statement. Any item can be marked to require a one-time code sent separately before it can be opened or uploaded against, which defeats the case where a client's mailbox is itself compromised.
- Per-item one-time code requirement
- Optional passwords for clients who want one
- Session expiry and device-level session revocation
A log that answers the question you will actually be asked
The question is never "was there a log". It is "who opened my tax return, and when". Every view, upload, download, approval and permission change is recorded with actor, timestamp and IP address, and the log is exportable per client or per engagement without contacting us.
- Views recorded, not only uploads and downloads
- Permission changes recorded with who made them
- Self-service export, no support ticket required
Retention that matches the policy you already have
A practice has a retention policy. A portal that keeps everything forever quietly replaces it with a different one. Retention is set per client or per engagement, and a purge is performed and recorded so you can evidence that it happened.
- Retention configurable per client and per engagement type
- Purge on request, with the purge itself logged
- Full export before deletion, on demand
Where the data lives
Choose United States, Canada, the European Union or the United Kingdom at setup, and your firm's documents stay in that region. Sub-processors are listed publicly and we will tell you before the list changes.
- Region chosen at setup and not silently migrated
- Sub-processor list published and versioned
- Notice before any change to the list
What to put in your vendor questionnaire
If your firm runs a vendor review, send the questionnaire and we will complete it rather than pointing you back at this page. The questions worth insisting on are the ones a marketing page tends to answer with an adjective.
Ask any vendor, including us, to answer these in writing. An answer you cannot quote back later is not an answer.
- What exactly does the audit log record, and can you export it yourself?
- Where is the data held, and can it be moved without telling you?
- Who are the sub-processors, and are you told before that list changes?
- How is access revoked when a staff member leaves?
- What does a data export look like, and can you run one unaided?
The mechanics underneath
Every featureAudit trail
Views, downloads, approvals and permission changes with actor, time and IP, exportable by you.
Your brand, your domain
Requests arrive from your firm at your domain, which is the practical defense against clients being unable to tell you from a phishing attempt.
Client vault
Encrypted at rest with separately managed keys, retention set per client, full export on demand.
Roles and per-client access
Per-client staff grants, roles, and single sign-on on the Group plan, so access ends when an account is disabled.
Request lists
Per-item one-time codes for identification and other high-sensitivity items.
Approvals on the record
Approved documents stored with the full approval record rather than emailed back and forth.
Client documents are the most sensitive thing a firm holds
So the portal is built to hold them properly: encrypted, access granted one client at a time, and every action recorded. Nothing travels as an email attachment.
How FirmHello is built- Encrypted in transit and at rest
- TLS 1.3 on every connection and AES-256 encryption for stored documents, with keys managed separately from the data they protect.
- Access is per client, not per firm
- A client can only ever load their own space. Staff access is granted per client, so a junior can be given three files and nothing else.
- No documents in email
- Notifications tell a client that something is waiting and link them to the portal. The material itself never leaves it as an attachment.
- Complete audit trail
- Views, uploads, downloads, approvals and permission changes are all recorded with actor, time and IP, and the log is exportable.
- Retention you control
- Set how long documents live per client or per matter, and hold or purge on request, so the portal matches the retention policy you already have.
- Hosted in your region
- Choose United States, Canada, the EU or the United Kingdom, and your firm's data stays in that region.
Questions a reviewer should ask
Will you complete our vendor security questionnaire?
Yes. Send it to security@firmhello.com and a person who works on the product will complete it. Where something is not in place, the response will say so rather than writing around the question.
Who are your sub-processors?
The list is published and versioned, and we notify you before it changes. Ask and we will send you the current version along with the data flow it belongs to.
How are documents encrypted?
TLS 1.3 in transit, AES-256 at rest, with key material held in a separate managed service so that access to storage alone is not access to documents.
Can one client ever see another client's documents?
A client session is bound to a single client record, so there is no product feature that would render another client's material. Staff access is separately granted per client.
What happens if a client's email account is compromised?
Notifications contain no documents, so an attacker in the mailbox sees only that a firm is waiting on something. Items marked sensitive additionally require a one-time code sent through a separate channel.
Can we get the audit trail for an insurer or a regulator?
Yes, and without asking us. Export the log per client or per engagement yourself, at any time.
Where is our data stored?
In the region you choose at setup — United States, Canada, the European Union or the United Kingdom — and it is not migrated out of it.
Related
Where to go next
Every page on the site, grouped by the question it answers.
- Choosing a portal
- Security checklist — you are here
- Large firms
- Virtual tax firms
- Paperless practice
Ready when you are
If this is the level of detail you were looking for, the trial is free for 14 days.
No card and no sales call. If you would rather tell us about your firm first, use the longer form.