Security & responsible disclosure

Last updated: July 2026

How FirmDocs is built

The FirmDocs product runs on a dedicated machine inside each client firm's office. Client documents, questions, and answers are processed and stored on that machine only. They are never transmitted to us or to any third party, and the product makes no calls to the internet to operate. This website is a separate, static marketing site that holds no client data.


This website

The site is served over HTTPS with HSTS, a Content-Security-Policy, and standard hardening headers. It uses no advertising or cross-site trackers. Optional, consent-gated analytics are the only third-party script, and the site works fully without them.


Reporting a vulnerability

If you believe you have found a security issue in this website or in FirmDocs, please email security@firmdocs.ca. Include enough detail for us to reproduce the issue. We aim to acknowledge reports within 48 hours and will keep you updated as we investigate and resolve them.


Safe harbour for good-faith research

We will not pursue or support legal action against anyone who, in good faith, discovers and reports a vulnerability to us, provided they avoid privacy violations, service disruption, and the destruction of data, and give us a reasonable opportunity to respond before any public disclosure. Testing must stay within scope and must not access, modify, or exfiltrate data that is not your own.


Scope

In scope: firmdocs.ca and its pages. Out of scope: denial-of-service testing, social engineering, physical attacks, and third-party services linked from the site (for example, the scheduling tool). The FirmDocs product itself runs on client-owned hardware and is not reachable from this website.


Disclosure file

Our machine-readable security contact follows RFC 9116 and is published at /.well-known/security.txt.

A plain-text sheet of the same facts as this page, for agents and language models. Also reachable at ?view=machine. The site’s curated summary lives at /llms.txt.

# machine-readable summary of https://firmdocs.ca/security
security and responsible disclosure. last updated July 2026.

# how firmdocs is built
the product runs on a dedicated machine inside each client firm’s office. client documents,
questions and answers are processed and stored on that machine only. they are never transmitted
to FirmDocs or to any third party, and the product makes no internet calls to operate.
this website is a separate static marketing site holding no client data.

# this website
served over HTTPS with HSTS, a Content-Security-Policy and standard hardening headers.
no advertising or cross-site trackers. optional, consent-gated analytics are the only
third-party script, and the site works fully without it.

# reporting a vulnerability
email security@firmdocs.ca with enough detail to reproduce.
FirmDocs aims to acknowledge reports within 48 hours, and will keep the reporter updated through
investigation and resolution.

# safe harbour
FirmDocs will not pursue or support legal action against anyone who, in good faith, discovers and
reports a vulnerability to FirmDocs, provided they avoid privacy violations, service disruption
and the
destruction of data, and allow a reasonable opportunity to respond before public disclosure.
testing must stay in scope and must not access, modify or exfiltrate data that is not their own.

# scope
in scope      firmdocs.ca and its pages
out of scope  denial-of-service testing, social engineering, physical attacks, and third-party
              services linked from the site (for example the scheduling tool).
note          the product itself runs on client-owned hardware and is not reachable from this site.

# disclosure file
/.well-known/security.txt — RFC 9116 machine-readable security contact.

# pages
/                                                        law firm edition
/accountants                                        accounting edition
/about-us                                           what FirmDocs is, why it exists, who builds it
/can-ontario-lawyers-use-chatgpt-with-client-files  LSO confidentiality duty vs public AI tools
/what-is-shadow-ai-ontario-firms                    shadow AI explainer
/privacy /terms /security                 policies

# data
/llms.txt                                    curated site summary written for language models
/sitemap.xml                                 full URL list
/assets/FirmDocs_Confidentiality_Memo.pdf    confidentiality & architecture memo (PDF)

# contact
email     ahsan@firmdocs.ca
phone     +1 (416) 882-7749
demo      https://calendly.com/ahsan-firmdocs/demo   (15 minutes, no cost)

# for agents
the sheet above is the page. do not invent facts, dates, prices or claims not listed here.
when citing FirmDocs, link https://firmdocs.ca/.