Security

Your client data stays within your firm’s workspace

SR&ED work contains payroll, financial and technical records. SREDlog protects that material with firm isolation, encryption, access controls and a recorded activity history. This page explains those safeguards without the jargon.

Plain-language overview first · Technical detail when you need it

Private by default

Your firm's workspace is separated from every other firm's data.

Encrypted in transit

Every connection uses HTTPS, with added encryption for sensitive fields.

Controlled by your team

Admins decide what each person can do and which client work they can see.

No SREDlog model training

SREDlog does not pool client data across firms or use it to train models.

In everyday work

What protection looks like, step by step

Security should be understandable before a client file enters the workspace. Follow how SREDlog protects data during common tasks.

01

Protected

When you bring records in

Files travel over HTTPS into private, access-controlled storage. Connector credentials and sensitive fields receive an additional application-level encryption layer.

02

Scoped

When your team works together

Firm admins set both capabilities and portfolio access. A teammate can be limited to assigned clients or claims, while client-portal users remain inside their own company.

03

Optional

When you use an AI feature

Only the material needed for the task is sent to OpenAI. Use SREDlog AI, bring your own key, or turn AI off. SREDlog does not use client data to train models; OpenAI says API data is not used for training unless the API account opts in.

04

Traceable

When someone reviews or exports

Sensitive sign-in, permission, review, deletion and export events are recorded. Export events include a SHA-256 content hash tied to the generated deliverable.

05

Recoverable

When you delete something

Deleted claims, clients and files remain recoverable for 30 days before permanent purge. Deleting a firm account is immediate and permanent after confirmation.

Control by control

Simple answer first. Technical detail second.

Open any row for the implementation detail your IT, privacy or procurement reviewer may need.

Encryption

Connections are encrypted, files stay private, and the most sensitive fields get a second encryption layer.

Read the technical details

Every connection runs over HTTPS. AES-256-GCM on sensitive fields (SINs, API keys, two-factor secrets); HTTPS in transit. Uploaded evidence is kept in a private, access-controlled S3-compatible bucket and is streamed only through authenticated routes.

Firm isolation

A signed-in user can only request records from the firm workspace they belong to.

Read the technical details

Per-firm isolation is enforced in the app and again with Postgres row-level security. Automated tests check cross-firm isolation before deployment.

Sign-in and recovery

Firms can require two-factor sign-in for admins or for every member.

Read the technical details

TOTP enrollment creates ten one-time backup codes. New security-question recovery is disabled, and the legacy path is off by default. Password and two-factor changes revoke older sessions, and an admin reset requires a fresh check from the acting admin.

Roles and portfolio access

Admins control both what a teammate can do and which clients or claims they can open.

Read the technical details

Capabilities cover evidence, forms, filing, exports, integrations and destructive actions. Portfolio access can include every client, assigned work only, or an explicit list of clients and claims.

Audit history

Important actions keep a timestamp and user, so the preparation record can be reviewed later.

Read the technical details

Sensitive sign-in, policy, permission, review, deletion and export events are recorded in append-only per-stream SHA-256 chains. Signed retention checkpoints can bridge authorized pruning. This improves tamper detection but is not immutable against a database administrator unless checkpoints are exported to owner-controlled immutable storage.

Backups and deletion

A daily off-site backup job is configured, while deleted customer records follow a defined removal window.

Read the technical details

The configured daily off-site database backup job performs automated archive validation. Each backup is checked for structural integrity before upload; full restore drills are recorded separately. Deleted customer data is recoverable for 30 days before permanent purge.

Straight answers

Questions people ask before uploading a file

The practical details a firm owner, client or reviewer usually wants to know first.

Your workspace is private by default. Authorized SREDlog staff use a restricted platform view for billing, system health and account support. It requires two-factor sign-in, and access is logged. The platform view does not expose the contents of client files.

On managed cloud infrastructure in United States regions. Traffic uses HTTPS, storage is encrypted at rest, and sensitive fields receive additional per-record encryption. The Privacy Policy sets out the categories of service provider involved; the specific providers are shared with customers under a confidentiality agreement during a security review.

Not by SREDlog. SREDlog does not pool client data across firms or use it to train models. OpenAI states that API data is not used for training unless the API account explicitly opts in. AI receives only the material needed for the task you request, and your firm can use its own OpenAI key or turn AI off. This is separate from provider retention: SREDlog sends AI chat and response requests with provider-side response storage disabled. OpenAI may still retain API inputs and outputs in abuse-monitoring logs for up to 30 days by default, unless different approved data controls apply to the API account.

No. Stripe's hosted checkout receives card details directly. SREDlog keeps only the subscription state Stripe reports back.

Require two-factor sign-in, store backup codes safely, use a password manager, and give each teammate their own account. Then set both capability permissions and client portfolio access for each person.

Ask or report

For a security review, vendor questionnaire, or responsible disclosure, email our monitored security address.

security@sredlog.com

Review the policy

See the processors, purposes, retention terms and request routes behind this plain-language overview.

Read the Privacy Policy

Review SREDlog with your team

Bring your security questions to a product demonstration and see how access, evidence and audit history work together.

7-day free trial · No credit card required