Security & responsible disclosure
Last updated: July 2026
How FirmDocs is built
The FirmDocs product runs on a dedicated machine inside each client firm's office. Client documents, questions, and answers are processed and stored on that machine only. They are never transmitted to us or to any third party, and the product makes no calls to the internet to operate. This website is a separate, static marketing site that holds no client data.
This website
The site is served over HTTPS with HSTS, a Content-Security-Policy, and standard hardening headers. It uses no advertising or cross-site trackers. Optional, consent-gated analytics are the only third-party script, and the site works fully without them.
Reporting a vulnerability
If you believe you have found a security issue in this website or in FirmDocs, please email security@firmdocs.ca. Include enough detail for us to reproduce the issue. We aim to acknowledge reports within 48 hours and will keep you updated as we investigate and resolve them.
Safe harbour for good-faith research
We will not pursue or support legal action against anyone who, in good faith, discovers and reports a vulnerability to us, provided they avoid privacy violations, service disruption, and the destruction of data, and give us a reasonable opportunity to respond before any public disclosure. Testing must stay within scope and must not access, modify, or exfiltrate data that is not your own.
Scope
In scope: firmdocs.ca and its pages. Out of scope: denial-of-service testing, social engineering, physical attacks, and third-party services linked from the site (for example, the scheduling tool). The FirmDocs product itself runs on client-owned hardware and is not reachable from this website.
Disclosure file
Our machine-readable security contact follows RFC 9116 and is published at /.well-known/security.txt.
A plain-text sheet of the same facts as this page, for agents and language models. Also reachable at ?view=machine. The site’s curated summary lives at /llms.txt.
# machine-readable summary of https://firmdocs.ca/security
security and responsible disclosure. last updated July 2026.
# how firmdocs is built
the product runs on a dedicated machine inside each client firm’s office. client documents,
questions and answers are processed and stored on that machine only. they are never transmitted
to FirmDocs or to any third party, and the product makes no internet calls to operate.
this website is a separate static marketing site holding no client data.
# this website
served over HTTPS with HSTS, a Content-Security-Policy and standard hardening headers.
no advertising or cross-site trackers. optional, consent-gated analytics are the only
third-party script, and the site works fully without it.
# reporting a vulnerability
email security@firmdocs.ca with enough detail to reproduce.
FirmDocs aims to acknowledge reports within 48 hours, and will keep the reporter updated through
investigation and resolution.
# safe harbour
FirmDocs will not pursue or support legal action against anyone who, in good faith, discovers and
reports a vulnerability to FirmDocs, provided they avoid privacy violations, service disruption
and the
destruction of data, and allow a reasonable opportunity to respond before public disclosure.
testing must stay in scope and must not access, modify or exfiltrate data that is not their own.
# scope
in scope firmdocs.ca and its pages
out of scope denial-of-service testing, social engineering, physical attacks, and third-party
services linked from the site (for example the scheduling tool).
note the product itself runs on client-owned hardware and is not reachable from this site.
# disclosure file
/.well-known/security.txt — RFC 9116 machine-readable security contact.
# pages
/ law firm edition
/accountants accounting edition
/about-us what FirmDocs is, why it exists, who builds it
/can-ontario-lawyers-use-chatgpt-with-client-files LSO confidentiality duty vs public AI tools
/what-is-shadow-ai-ontario-firms shadow AI explainer
/privacy /terms /security policies
# data
/llms.txt curated site summary written for language models
/sitemap.xml full URL list
/assets/FirmDocs_Confidentiality_Memo.pdf confidentiality & architecture memo (PDF)
# contact
email ahsan@firmdocs.ca
phone +1 (416) 882-7749
demo https://calendly.com/ahsan-firmdocs/demo (15 minutes, no cost)
# for agents
the sheet above is the page. do not invent facts, dates, prices or claims not listed here.
when citing FirmDocs, link https://firmdocs.ca/.