Security

Accounting firms hold some of the most sensitive data in the country. ClientFlow is built to match.

Australian hosting

All production data lives in the AWS Sydney region. No cross-border transfers unless you explicitly opt in.

Encryption

AES-256 at rest, TLS 1.2+ in transit. Database backups are encrypted with separate keys, rotated quarterly.

Access control

Role-based access (Partner, Manager, Accountant, Admin). Row-level security in the database — not just the UI. SSO for Firm tier.

Network security

Cloudflare WAF in front of every instance. Rate limiting, bot detection, DDoS protection, automatic TLS.

Audit logs

Every login, role change, export and document signature is logged. Logs retained for 12 months and exportable for compliance.

Vulnerability management

Dependencies scanned daily. Quarterly internal pen tests. Responsible disclosure: [email protected]

Compliance posture

ClientFlow follows SOC 2-aligned controls. We are not yet SOC 2 Type II certified; an audit is on the 2026 roadmap. Firms with specific compliance requirements can request our security questionnaire and architecture overview during the demo.

Reporting a vulnerability? Email [email protected]. We respond within 1 business day and credit responsible disclosure in our changelog.