You hold your clients' most sensitive financial data. OneFirmOS is built to protect it at every layer — encrypted, isolated per firm, and hosted in your region.
The controls that protect your firm's data, day one.
Sensitive fields are encrypted in the database, on top of AES-256 storage-level encryption across the platform.
All traffic is protected with modern TLS (1.3), so data is encrypted end-to-end between you and OneFirmOS.
Data and documents are hosted in-region — Canada (AWS ca-central-1) or the US — based on each client's location.
Every firm's data is walled off with database-enforced row-level security — one firm can never see another's.
Granular roles and permissions mean each team member sees exactly what their job requires — and nothing more.
Add a second factor to sign-in for stronger account protection against compromised passwords.
Automated, encrypted backups run daily so your data can be recovered — with point-in-time restore.
Administrative activity is logged, and every e-signature carries a tamper-evident audit trail.
Signatures capture IP, device, timestamp and a document hash, with a downloadable signing certificate.
Credentials and tokens are held in a managed secrets store — never in code — with least-privilege access.
Configurable retention, legal hold and automated purge keep records exactly as long as compliance requires.
A public status page for real-time platform availability and incident history.
Organized the way a security team would review it. Expand any topic for specifics.
What's in place today, and what we're investing in next. We only claim what we actually do.
Need our security documentation for a review? Email support@onefirmos.com and we'll share what you need.
Book a walkthrough, or request our security documentation for your review.