profirm.ai
Sign inBook a demo

Security & compliance

Built to survive a peer review.

Access is a permission model, not a job title. Overrides are possible, and expensive: each one demands a written reason and writes a HIGH-severity row to the tenant audit log.

Identity

MFA, backup codes, trusted devices

Per-user multi-factor with recovery codes, plus a trusted-device list a member or an admin can revoke.

Authorisation

Custom roles with a privilege ceiling

Define tenant roles at the permission level. A role manager can never grant beyond their own ceiling, re-checked again at approve time.

Change control

Role-change approvals

Role managers propose; approvers review. The proposal, the approver and the resulting permission set are all recorded.

Transparency

Access simulator & my permissions

Simulate what any role can open before granting it, and let every member see their own effective permissions.

Accountability

Tenant-wide audit log

Actor, action, target, severity and before/after detail on every privileged event, filterable by user, entity, severity and date range.

Escalation

Overrides cost something

Bypassing a prerequisite gate needs the permission, a reason of at least 30 characters, and it writes a HIGH-severity audit row per affected event.

Oversight

Impersonation, visibly

Support access runs as impersonation with a persistent banner in the UI and its own audit trail. No silent sessions.

Evidence

Peer-review packs

Generate a JSON detail file and a PDF cover summary for any window, so a reviewer works from the record rather than from reassembled paper.

Continuity

Backups & exports

Tenant backups plus a firm-wide export register, every GSTR, Tally, peer-review pack and AI draft ever generated, re-downloadable.

Certifications

We publish our current posture rather than badges we haven't earned. Ask for the security pack and we'll send the controls list, data-residency options, sub-processor register and our DPDP alignment statement as they stand today.

Request the security pack