SECURITY

Controls designed for sensitive professional work

PracticeFlow 360 combines tenant-scoped access, private document delivery, tamper-evident audit history and recovery controls that must pass release gates before general availability.

Tenant scoped

Central route and repository checks keep firm records within their organisation.

Private documents

Storage is private and downloads use short-lived signed access after authorization.

Step-up protection

Sensitive superadmin actions require a recent MFA verification.

Tamper-evident history

Audit entries are sequenced, hash chained and anchored to an independent account.

Encrypted recovery copies

Independent database exports and document replicas use a dedicated KMS key.

Verified recovery

GA requires an isolated database, authentication and document-hash restore drill.

Privacy workflows

Exports have manifests and checksums; deletion cannot be marked complete before erasure.

Portable data

Administrators can request a complete tenant export with original documents.

What “ready for GA” means

Security claims are release gates, not decorative promises. The release remains in pilot until the controls below have current evidence.

  • Independent security assessment with no unresolved P0 or P1 finding
  • Successful tenant-isolation and unscoped-query tests
  • Completed restore drill within the four-hour target
  • Secrets rotation and sensitive-data scrubbing verification
  • Private Storage policies and independent backup account confirmed