Your client data stays within your firm’s workspace
SR&ED work contains payroll, financial and technical records. SREDlog protects that material with firm isolation, encryption, access controls and a recorded activity history. This page explains those safeguards without the jargon.
Plain-language overview first · Technical detail when you need it
Private by default
Your firm's workspace is separated from every other firm's data.
Encrypted in transit
Every connection uses HTTPS, with added encryption for sensitive fields.
Controlled by your team
Admins decide what each person can do and which client work they can see.
No SREDlog model training
SREDlog does not pool client data across firms or use it to train models.
What protection looks like, step by step
Security should be understandable before a client file enters the workspace. Follow how SREDlog protects data during common tasks.
Protected
When you bring records in
Files travel over HTTPS into private, access-controlled storage. Connector credentials and sensitive fields receive an additional application-level encryption layer.
Scoped
When your team works together
Firm admins set both capabilities and portfolio access. A teammate can be limited to assigned clients or claims, while client-portal users remain inside their own company.
Optional
When you use an AI feature
Only the material needed for the task is sent to OpenAI. Use SREDlog AI, bring your own key, or turn AI off. SREDlog does not use client data to train models; OpenAI says API data is not used for training unless the API account opts in.
Traceable
When someone reviews or exports
Sensitive sign-in, permission, review, deletion and export events are recorded. Export events include a SHA-256 content hash tied to the generated deliverable.
Recoverable
When you delete something
Deleted claims, clients and files remain recoverable for 30 days before permanent purge. Deleting a firm account is immediate and permanent after confirmation.
Simple answer first. Technical detail second.
Open any row for the implementation detail your IT, privacy or procurement reviewer may need.
Encryption
Connections are encrypted, files stay private, and the most sensitive fields get a second encryption layer.
Read the technical details
Every connection runs over HTTPS. AES-256-GCM on sensitive fields (SINs, API keys, two-factor secrets); HTTPS in transit. Uploaded evidence is kept in a private, access-controlled S3-compatible bucket and is streamed only through authenticated routes.
Firm isolation
A signed-in user can only request records from the firm workspace they belong to.
Read the technical details
Per-firm isolation is enforced in the app and again with Postgres row-level security. Automated tests check cross-firm isolation before deployment.
Sign-in and recovery
Firms can require two-factor sign-in for admins or for every member.
Read the technical details
TOTP enrollment creates ten one-time backup codes. New security-question recovery is disabled, and the legacy path is off by default. Password and two-factor changes revoke older sessions, and an admin reset requires a fresh check from the acting admin.
Roles and portfolio access
Admins control both what a teammate can do and which clients or claims they can open.
Read the technical details
Capabilities cover evidence, forms, filing, exports, integrations and destructive actions. Portfolio access can include every client, assigned work only, or an explicit list of clients and claims.
Audit history
Important actions keep a timestamp and user, so the preparation record can be reviewed later.
Read the technical details
Sensitive sign-in, policy, permission, review, deletion and export events are recorded in append-only per-stream SHA-256 chains. Signed retention checkpoints can bridge authorized pruning. This improves tamper detection but is not immutable against a database administrator unless checkpoints are exported to owner-controlled immutable storage.
Backups and deletion
A daily off-site backup job is configured, while deleted customer records follow a defined removal window.
Read the technical details
The configured daily off-site database backup job performs automated archive validation. Each backup is checked for structural integrity before upload; full restore drills are recorded separately. Deleted customer data is recoverable for 30 days before permanent purge.
Questions people ask before uploading a file
The practical details a firm owner, client or reviewer usually wants to know first.
Your workspace is private by default. Authorized SREDlog staff use a restricted platform view for billing, system health and account support. It requires two-factor sign-in, and access is logged. The platform view does not expose the contents of client files.
On managed cloud infrastructure in United States regions. Traffic uses HTTPS, storage is encrypted at rest, and sensitive fields receive additional per-record encryption. The Privacy Policy sets out the categories of service provider involved; the specific providers are shared with customers under a confidentiality agreement during a security review.
Not by SREDlog. SREDlog does not pool client data across firms or use it to train models. OpenAI states that API data is not used for training unless the API account explicitly opts in. AI receives only the material needed for the task you request, and your firm can use its own OpenAI key or turn AI off. This is separate from provider retention: SREDlog sends AI chat and response requests with provider-side response storage disabled. OpenAI may still retain API inputs and outputs in abuse-monitoring logs for up to 30 days by default, unless different approved data controls apply to the API account.
No. Stripe's hosted checkout receives card details directly. SREDlog keeps only the subscription state Stripe reports back.
Require two-factor sign-in, store backup codes safely, use a password manager, and give each teammate their own account. Then set both capability permissions and client portfolio access for each person.
Ask or report
For a security review, vendor questionnaire, or responsible disclosure, email our monitored security address.
security@sredlog.comReview the policy
See the processors, purposes, retention terms and request routes behind this plain-language overview.
Read the Privacy PolicyReview SREDlog with your team
Bring your security questions to a product demonstration and see how access, evidence and audit history work together.
7-day free trial · No credit card required
Protected view
Click to unlock
Open the lock to reveal how SREDlog protects client data.