Security

Version 2.7 · Last revised: July 23, 2026

Filemark processes sensitive corporate tax data for Canadian accounting firms. This page lists the technical and organizational controls we have in place today. For further details, contact security@filemark.ca.

AI Privacy

  • Filemark uses Amazon Bedrock for clearly defined purposes. Please refer to your firm’s AI settings for more information.
  • One current, versioned authorization must be recorded for the client before any AI purpose may process that client’s data. A firm-wide master control and per-purpose controls can further restrict use; withdrawing the client authorization disables all AI processing for that client.
  • Only context relevant to the authorized purpose is sent. Calls originate in Canada and may be processed in Canada or the United States.
  • Filemark’s persistent application database, files, and saved AI results remain in Canada. Bedrock does not retain prompts or outputs, and they are not shared with the foundation-model provider or used to train base models. Filemark may log AI prompts and outputs in Canada on AWS under a 90-day retention policy.
  • AI outputs are decision support for practitioner review. Deterministic or manual workflows remain available when AI is not authorized or is disabled, and a process-wide kill switch exists for emergencies.

Data Protection

  • Encryption in transit: TLS 1.3 preferred, TLS 1.2 minimum, with HSTS preload.
  • Encryption at rest: AES-256 on database and file storage.
  • Connector credentials: encrypted with per-tenant keys so a single key compromise cannot decrypt another firm’s secrets.
  • Tenant isolation: every data access is scoped to the requesting organization, so one firm’s data is never reachable from another firm’s session.
  • Firewall allowlisting: a stable egress IP for firms that need to allowlist Filemark’s outbound traffic is available on request.

Authentication & Access

  • Email-and-password authentication through a managed identity provider.
  • Multi-factor authentication (TOTP / authenticator app) available.
  • Sessions validated server-side; tokens are short-lived and rotated automatically.
  • Idle sessions are automatically signed out after 30 minutes of inactivity.
  • Sign-in, sign-up, and all API endpoints are rate-limited.

Audit Logging

  • User actions logged for file uploads, exports, AI runs, integration calls, and document extraction.
  • AI activity is logged with its purpose and operational metadata such as model, token use, latency, and errors.
  • Connector audit log records which integration was called, when, by which user, and which data categories were involved (no file contents, no credential values).
  • Authentication and administrative events are captured in the platform audit trail.
  • Audit logs are organization-scoped and retained for the same six-year window as engagement data.

Infrastructure

  • Filemark runs on Amazon Web Services in the Canada (ca-central-1) region: managed compute, an encrypted managed database, object storage, managed authentication, a per-tenant secrets vault, and transactional email — all hosted in Canada.
  • Client-portal uploads are malware-scanned before processing.
  • AI inference uses Amazon Bedrock, as described under AI Privacy above.
  • Real-time service status: filemark.statuspage.io.

Backup & Resilience

  • Point-in-time recovery on the managed database, in the Canada (ca-central-1) region.
  • Object storage replicated within ca-central-1.
  • Backups are encrypted with the same AES-256 standard as production data and never leave Canada.
  • Disaster-recovery objectives and tested restore procedures are documented in our internal runbook and available to enterprise customers under NDA.

Subprocessors

The third parties that process Filemark customer data on our behalf — together with their region, role, and cross-border posture for each — are listed at filemark.ca/legal/subprocessors. That page is the canonical public disclosure and is updated whenever a subprocessor is added, removed, or has a material change.

Breach Notification

If Filemark becomes aware of a breach of security safeguards involving customer data that creates a real risk of significant harm, we notify the affected customer’s account administrators without undue delay and in any event within 72 hours of confirming the breach, and notify the required regulators, as detailed in the Service Privacy Policy. Suspected breaches can be reported confidentially to security@filemark.ca.

Automated Decision Support

Filemark’s tax engine performs automated computations on uploaded data, but every output is decision-support intended for review and sign-off by a qualified Canadian tax practitioner. Filemark does not render a final decision based exclusively on automated processing within the meaning of Quebec Law 25 § 12.1. Full disclosure of the categories of personal information used, the principal factors and parameters, and the right to request human review is set out in the Service Privacy Policy.

Compliance

  • PIPEDA & Quebec Law 25 — in production; see the Service Privacy Policy
  • Data Processing Agreement (DPA) available on request to legal@filemark.ca

Responsible Disclosure

We encourage coordinated vulnerability disclosures. If you believe you have found a security issue in Filemark, please contact us at security@filemark.ca.

We commit to:

  • Acknowledging reports within 5 business days.
  • Investigating promptly and keeping you informed of progress.
  • Not pursuing legal action against good-faith security researchers.
Filemark | Security