Security & Privacy

Security designed for private firm knowledge.

AskFirmBrain is built on Microsoft Azure and uses separate firm workspaces, role-based access, encryption, and secure handling of uploaded documents.

Built on Microsoft Azure

AskFirmBrain uses Microsoft Azure services, including Azure OpenAI, Azure AI Search, and Azure Blob Storage, to securely store, index, retrieve, and process firm knowledge.

Encrypted data

Data is encrypted in transit using HTTPS/TLS and encrypted at rest using Microsoft Azure’s built-in encryption.

Private AI processing

Customer prompts, completions, embeddings, and uploaded firm content are not used to train foundation models without customer permission.

Separate firm workspaces

Core application data is scoped by FirmId so firm documents, users, chats, settings, templates, checklists, and usage are separated by firm workspace.

Role-based access control

The app supports SuperAdmin, Admin, and User roles. Admin-only settings, team management, document management, templates, and checklist actions use server-side authorization checks.

Document-level controls

Documents are scoped to the firm workspace, can be managed through controlled document workflows, and support document-level permissions and deletion controls for uploaded files and related records.

Audit logs

Security and firm actions such as sign-in events and selected create, update, archive, and delete actions are recorded where audit logging is implemented.

Retention options

Optional data retention limits can be configured by deployment or added for firm-specific policies, including document cleanup and record-retention workflows.

Human verification

AskFirmBrain helps retrieve and summarize firm knowledge, but tax advice must be reviewed and verified by a qualified human professional before client use.

Have a security question?

Contact us before uploading sensitive firm data if you need to discuss deployment, storage configuration, access control, or privacy requirements.

Contact Us