● Trust & Security

Security your clients can count on

You hold your clients' most sensitive financial data. OneFirmOS is built to protect it at every layer — encrypted, isolated per firm, and hosted in your region.

🔒 AES-256 at rest 🔐 TLS 1.3 in transit 🇨🇦🇺🇸 CA / US residency
What's in place

Security built into every layer

The controls that protect your firm's data, day one.

Encryption at rest

Sensitive fields are encrypted in the database, on top of AES-256 storage-level encryption across the platform.

Encryption in transit

All traffic is protected with modern TLS (1.3), so data is encrypted end-to-end between you and OneFirmOS.

Data residency (Canada / US)

Data and documents are hosted in-region — Canada (AWS ca-central-1) or the US — based on each client's location.

Tenant isolation

Every firm's data is walled off with database-enforced row-level security — one firm can never see another's.

Role-based access control

Granular roles and permissions mean each team member sees exactly what their job requires — and nothing more.

Multi-factor authentication

Add a second factor to sign-in for stronger account protection against compromised passwords.

Daily encrypted backups

Automated, encrypted backups run daily so your data can be recovered — with point-in-time restore.

Audit logging

Administrative activity is logged, and every e-signature carries a tamper-evident audit trail.

Tamper-evident e-signatures

Signatures capture IP, device, timestamp and a document hash, with a downloadable signing certificate.

Secrets management

Credentials and tokens are held in a managed secrets store — never in code — with least-privilege access.

Retention & legal hold

Configurable retention, legal hold and automated purge keep records exactly as long as compliance requires.

Status page Coming soon

A public status page for real-time platform availability and incident history.

The details

A closer look under the hood

Organized the way a security team would review it. Expand any topic for specifics.

Cloud & infrastructure security
How the platform is hosted, encrypted, isolated at the network level, and recovered.
Hosting & infrastructure
OneFirmOS runs entirely on Amazon Web Services. Application compute runs on Amazon ECS Fargate, the database on managed Amazon RDS for PostgreSQL, and documents in Amazon S3 — all inside a private virtual network (VPC). The database is not publicly accessible; only the application can reach it. Public traffic enters through an application load balancer that redirects all HTTP to HTTPS.
Encryption
In transit, all connections use modern TLS (1.3). At rest, the database and document storage are encrypted with AES-256, and the most sensitive fields carry an additional layer of application-level encryption. Encryption keys are managed by AWS Key Management Service (KMS).
Network security
Databases and internal services run in private subnets with security groups that permit only the traffic they need. The only public entry point is the HTTPS load balancer — there is no direct public access to the database or file storage.
Backups & recovery
Amazon RDS takes automated, encrypted backups daily and supports point-in-time restore; snapshots inherit the same AES-256 encryption as the live database. Documents in S3 are durably stored across multiple facilities. Formal recovery-time and recovery-point objectives (RTO/RPO) are on our roadmap.
Secrets & key management
Application secrets, database credentials and third-party tokens live in AWS Secrets Manager — never in source code or container images. Deployments authenticate to AWS with short-lived, federated credentials (OIDC), so there are no long-lived cloud keys to leak. Access to production follows least-privilege principles.
Web application (product) security
How the application protects accounts, data and the code that ships to it.
Authentication & access control
Passwords are salted and hashed; sessions use signed tokens scoped to the user and their firm. Within a firm, access is governed by granular role-based permissions, so each team member sees only what their role allows. Multi-factor authentication is supported for stronger sign-in protection.
Tenant isolation
OneFirmOS is multi-tenant with isolation enforced at the database using PostgreSQL row-level security. The signed-in firm is pinned on every database connection and every query is automatically scoped to that firm — so one firm's data can never be returned to another. This isolation is covered by automated tests.
Secure development
Changes ship through an automated CI/CD pipeline into a staging environment that mirrors production before release. Infrastructure is defined as code and version-controlled, and releases are rolled out in a controlled way. Independent third-party penetration testing is on our roadmap.
Audit logging & e-signatures
Administrative and platform actions — sign-ins, firm and plan changes, configuration changes, data exports and impersonation — are recorded in an activity log. Every proposal e-signature captures a tamper-evident audit trail (IP address, device, timestamp and a document hash) with a downloadable signing certificate.
Data retention & deletion
Firms can configure retention periods, apply legal holds, and have records automatically purged when retention lapses; storage limits are enforced per firm. Firms can export their data at any time, and data is deleted after termination in line with the agreement.
Availability & monitoring
The platform runs on managed, health-checked AWS services with controlled, rolling deployments to minimize disruption. A public status page and a formal uptime commitment (SLA) are on our roadmap.
Compliance & privacy
How we handle privacy law, data processing, your rights, and certifications.
Privacy law alignment (PIPEDA / Law 25)
Our practices align with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and with Quebec's Law 25 where we serve Quebec firms or their clients. Our privacy policy is published and kept current, and data residency follows each client's location (Canada or US).
Data processing & subprocessors
For the client data firms store in OneFirmOS, we act as a service provider processing it on the firm's instructions, governed by a Data Processing Agreement. We rely on a limited set of vetted subprocessors — AWS (hosting), Stripe (payments), SendGrid (email), our AI providers, and Microsoft/Google for optional connected mailboxes — under contracts requiring a comparable level of protection.
Your data & your rights
Firms own their data. We provide tools to access, correct, export and delete personal information so firms can meet access and correction requests, and we assist with data-subject and regulator inquiries. On termination, firms can export their data before it is deleted.
Certifications & roadmap
We do not currently hold a formal certification; a SOC 2 Type II examination is on our roadmap. We're glad to share our security documentation — including our Security & Privacy Schedule and Data Processing Agreement — for your review. Email support@onefirmos.com.
Transparency

Compliance roadmap

What's in place today, and what we're investing in next. We only claim what we actually do.

Available today

In production now
  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Field-level encryption of sensitive data
  • Database-enforced tenant isolation (row-level security)
  • Role-based access control
  • Canadian & US data residency
  • Tamper-evident e-signature audit trail
  • Configurable retention, legal hold & auto-purge
  • Managed secrets & least-privilege deployment
  • PIPEDA-aligned privacy practices

On our roadmap

Planned — not yet available
  • SOC 2 Type II examination
  • Public status page with incident history
  • Enforced MFA & SSO (SAML) options
  • Independent third-party penetration testing
  • Centralized security logging & alerting
  • Documented disaster-recovery targets (RPO/RTO)
  • Quebec Law 25 program (as we serve Quebec)

Need our security documentation for a review? Email support@onefirmos.com and we'll share what you need.

Let's talk

See how OneFirmOS protects your firm

Book a walkthrough, or request our security documentation for your review.

Book a demo Request security docs