Security and trust

Finance software should make trust easier to review.

FIRMA is the financial operating system for operators running one entity or many. Sensitive finance work lives behind authenticated, isolated workspaces, while public marketing pages stay free of any place to enter sensitive data.

Request security reviewReview AI boundaries
Platform controls

The controls behind every FIRMA workspace.

Encryption in transit

Traffic to FIRMA is served over TLS. Data moves between your browser and FIRMA over encrypted connections.

Tenant isolation with row-level security

Tenant-scoped tables are protected by PostgreSQL row-level security with FORCE ROW LEVEL SECURITY enabled, so one workspace cannot read another workspace data, even if application code has a bug.

Step-up MFA and idle timeout

Multi-factor step-up verification is required before sensitive surfaces open, and sessions end automatically after 30 minutes of inactivity.

Audit logging with retention

Security-relevant events are recorded to a FIRMA audit log retained for six years, so account activity can be reviewed after the fact.

Key-rotation discipline

Service credentials and keys are rotated on a disciplined schedule, and rotation is part of the incident-response process.

Business Associate Agreement on request

For eligible healthcare tenants, a BAA is available on request and must be in place before HIPAA-enabled surfaces are activated. FIRMA does not make a blanket HIPAA-compliant claim.

A SOC 2 examination is in progress. FIRMA does not present SOC 2 or HIPAA as completed compliance programs. Current status and documentation are shared through the demo and customer-success process.

Trust posture

Designed for review-first finance operations.

Access control by default

FIRMA is designed around authenticated workspaces, role-aware access, and separation between public marketing pages and private finance workflows.

Human approval before financial action

AI can help explain, draft, and route finance work. Posting, migration, and account-specific decisions stay review-first and evidence-aware.

Public AI guide boundaries

The public AI Guide is for product education and business planning questions. It tells visitors not to enter bank, tax, card, payroll, password, or customer financial records.

Entity and client separation

FIRMA messaging and product design emphasize clean separation between entities, customers, documents, and finance review queues.

Reviewable operations

Financial workflows should leave context for the owner, bookkeeper, or accountant to review. The site does not promise automated professional judgment.

Evidence-based claims

Public pages avoid certification, compliance, savings, and outcome claims unless accepted evidence exists and the claim is explicitly cleared.

Public AI boundaries

Helpful answers without collecting sensitive finance records.

The public FIRMA AI Guide should help buyers understand products, workflows, comparisons, migration planning, and business finance questions. Account-specific financial work belongs in controlled channels after the right scope is clear.

  • CheckDo not enter bank account numbers, routing numbers, card numbers, SSNs, EINs, tax IDs, passwords, payroll details, or private customer financial records.
  • CheckUse public AI answers for education, product routing, and planning, not professional accounting, tax, legal, payroll, or compliance advice.
  • CheckMove account-specific questions into a controlled sales, onboarding, or customer workspace before sharing sensitive business information.
Buyer review checklist

What to review before bringing finance workflows into any platform.

  1. Confirm who can access each entity, client, account, and document set.
  2. Keep source documents close to invoices, banking review, and reports.
  3. Review AI-generated suggestions before financial posting or migration decisions.
  4. Invite accountant or bookkeeper review when financial statements, tax treatment, or close decisions matter.
  5. Route security documentation requests through the demo or customer-success process.
FAQ

What is FIRMA's SOC 2 status?

A SOC 2 examination is in progress. FIRMA does not present SOC 2 as a completed compliance program. Buyers can request current status through the demo process.

What is FIRMA's HIPAA posture?

FIRMA does not make a blanket HIPAA-compliant claim. For eligible healthcare tenants, a BAA is available on request and must be in place, with MFA verification, before HIPAA-enabled surfaces are activated.

How is one customer data kept separate from another?

Tenant-scoped data is protected with PostgreSQL row-level security using FORCE ROW LEVEL SECURITY, so isolation is enforced at the database layer rather than relying on application code alone.

Can I enter private financial details into the public FIRMA AI Guide?

No. The public AI Guide is for education and product routing only. Do not enter bank, tax, payroll, card, password, or private customer financial records.

Does FIRMA replace my accountant, CPA, tax advisor, or attorney?

No. FIRMA can support finance workflows and owner review, but it does not replace professional accounting, tax, legal, payroll, or compliance judgment.

Security questions

Route security review through the right channel.

For product security questions, implementation scope, or vendor review materials, request a demo and LUCA will route the conversation to the right owner.

Request demoEmail security