Security
Accounting firms hold some of the most sensitive data in the country. ClientFlow is built to match.
Australian hosting
All production data lives in the AWS Sydney region. No cross-border transfers unless you explicitly opt in.
Encryption
AES-256 at rest, TLS 1.2+ in transit. Database backups are encrypted with separate keys, rotated quarterly.
Access control
Role-based access (Partner, Manager, Accountant, Admin). Row-level security in the database — not just the UI. SSO for Firm tier.
Network security
Cloudflare WAF in front of every instance. Rate limiting, bot detection, DDoS protection, automatic TLS.
Audit logs
Every login, role change, export and document signature is logged. Logs retained for 12 months and exportable for compliance.
Vulnerability management
Dependencies scanned daily. Quarterly internal pen tests. Responsible disclosure: [email protected]
Compliance posture
ClientFlow follows SOC 2-aligned controls. We are not yet SOC 2 Type II certified; an audit is on the 2026 roadmap. Firms with specific compliance requirements can request our security questionnaire and architecture overview during the demo.
Reporting a vulnerability? Email [email protected]. We respond within 1 business day and credit responsible disclosure in our changelog.