Our Security
Security & responsible disclosure
Last updated: July 2026
How FirmDocs is built
The FirmDocs product runs on a dedicated machine inside each client firm's office. Client documents, questions, and answers are processed and stored on that machine only. They are never transmitted to us or to any third party, and the product makes no calls to the internet to operate. This website is a separate, static marketing site that holds no client data.
This website
The site is served over HTTPS with HSTS, a Content-Security-Policy, and standard hardening headers. It uses no advertising or cross-site trackers. Optional, consent-gated analytics are the only third-party script, and the site works fully without them.
Reporting a vulnerability
If you believe you have found a security issue in this website or in FirmDocs, please email security@firmdocs.ca. Include enough detail for us to reproduce the issue. We aim to acknowledge reports within 48 hours and will keep you updated as we investigate and resolve them.
Safe harbour for good-faith research
We will not pursue or support legal action against anyone who, in good faith, discovers and reports a vulnerability to us, provided they avoid privacy violations, service disruption, and the destruction of data, and give us a reasonable opportunity to respond before any public disclosure. Testing must stay within scope and must not access, modify, or exfiltrate data that is not your own.
Scope
In scope: firmdocs.ca and its pages. Out of scope: denial-of-service testing, social engineering, physical attacks, and third-party services linked from the site (for example, the scheduling tool). The FirmDocs product itself runs on client-owned hardware and is not reachable from this website.
Disclosure file
Our machine-readable security contact follows RFC 9116 and is published at /.well-known/security.txt.