Security First

Your Client Data, Protected

Enterprise-grade security and PIPEDA compliance designed specifically for CPA firms handling sensitive tax and financial data across Canada.

256-bit
AES Encryption
99.9%
Uptime SLA
PIPEDA
Compliant
SOC 2
Aligned
Data Protection

Your Data is Encrypted at Every Layer ENSURES COMPLIANCE

Multiple layers of encryption and security ensure your clients' sensitive financial information is protected at all times.

Encryption in Transit

All data transmitted between your browser and our servers is protected with TLS 1.2+ encryption. Every API call, file upload, and page load is secured with industry-standard transport layer security.

256-bit bank-grade encryption

Encryption at Rest

All stored data, including client records, tax documents, and financial information, is encrypted using AES-256 encryption. Even in the unlikely event of unauthorized physical access, your data remains unreadable.

AES-256 at-rest protection

Secure Canadian Hosting

Your data is hosted on secure infrastructure in Canada, ensuring compliance with Canadian data residency requirements. Your clients' information never leaves Canadian jurisdiction without your explicit consent.

100% Canadian data residency

Encrypted Credential Storage

Each firm's SMTP, SMS, and integration credentials are encrypted with dedicated AES-256 keys. Credentials are decrypted only at the moment of use and never stored in plaintext or shared between firms.

0 plain-text passwords

Automatic Backups

Your data is automatically backed up on a regular schedule with point-in-time recovery capabilities. Backups are encrypted and stored in geographically separate locations to protect against data loss from any single point of failure.

Daily point-in-time recovery
Access Control

Granular Access Controls ENSURES COMPLIANCE

Ensure the right people see the right data with role-based permissions, two-factor authentication, and comprehensive audit trails.

Role-Based Access

Four distinct permission levels ensure staff only access what they need.

  • Admin - Full system access
  • Manager - Team and client management
  • Staff - Assigned client access
  • ReadOnly - View-only access
4 configurable role levels

Two-Factor Authentication

Protect accounts with OTP verification delivered via email or SMS for every login.

  • Email-based OTP codes
  • SMS-based OTP codes
  • Configurable device remembrance
  • Adjustable expiry (1 hour to 1 week)
99.9% of attacks prevented

Session Management & Audit Logging

Automatic session timeouts and comprehensive logging of all user activity.

  • Automatic session timeout
  • Login and action audit trail
  • IP and device tracking
  • Security event notifications
Every action logged
Multi-Office Data Isolation

Complete Firm Isolation PROTECTS REVENUE

Every office and branch on MyCPACRM operates in a completely isolated environment. There is zero possibility of data crossing between offices.

Complete Data Isolation

Every database query is automatically filtered by firm. It is architecturally impossible for one firm to access another firm's client data, filings, documents, or communications.

0 cross-firm data access

Separate SMTP & SMS Credentials

Each firm configures their own email server and SMS provider. Client communications are always sent from your firm's own credentials, never from a shared system or another firm's configuration.

Per-firm secure isolation

Firm-Specific Storage

Document uploads and file storage are organized into firm-specific buckets. Access controls ensure documents uploaded by one firm cannot be accessed or enumerated by any other firm.

Separate containers per firm

Zero Cross-Firm Leakage

Background jobs, automated reminders, and scheduled tasks all verify firm context before execution. Each operation is scoped to a single firm with explicit security checks to prevent any cross-contamination.

0 incidents since launch
PIPEDA Compliant

Built for Canadian Privacy Law ENSURES COMPLIANCE

MyCPACRM is designed from the ground up to meet the requirements of the Personal Information Protection and Electronic Documents Act (PIPEDA), the federal privacy law governing how private-sector organizations collect, use, and disclose personal information.

Personal Information Protection

All personally identifiable information (SIN, BN, addresses, financial data) is encrypted and access-controlled.

Right to Access & Correct Data

Clients can request access to their personal information and have inaccuracies corrected at any time.

Data Export Capabilities

Export client data in CSV and PDF formats for portability, regulatory review, or migration purposes.

Data Retention Policies

Configurable retention policies ensure data is kept only as long as necessary and securely disposed of when no longer required.

Consent Management

Track and manage client consent for data collection, email communications, and SMS reminders with clear opt-in and opt-out controls.

Privacy by Design

Security and privacy considerations are built into every feature from the architectural design phase, not bolted on after the fact.

Infrastructure

Secure, Reliable Infrastructure PROTECTS REVENUE

Built on modern, hardened infrastructure with multiple layers of protection to ensure your practice runs without interruption.

Secure Cloud Hosting

Hosted on enterprise-grade cloud infrastructure

Regular Updates

Continuous security patches and updates

DDoS Protection

Protection against distributed attacks

SSL/TLS Everywhere

All connections encrypted end-to-end

24/7 Monitoring

Automated alerting and uptime monitoring

Compliance & Standards ENSURES COMPLIANCE

MyCPACRM aligns with the security frameworks and compliance standards that matter most to Canadian accounting firms.

PIPEDA

Fully compliant with the Personal Information Protection and Electronic Documents Act, Canada's federal privacy legislation governing how private-sector organizations handle personal information.

Full Canadian privacy compliance

CPA Canada Best Practices

Designed to align with CPA Canada's data handling best practices and guidelines for protecting client information in professional accounting engagements.

Industry standard alignment

OWASP Top 10 Protection

Protected against the OWASP Top 10 most critical web application security risks, including injection attacks, broken authentication, cross-site scripting, and insecure deserialization.

Top 10 vulnerability protection

Security FAQs

Common questions about how we protect your data.

Where is my data stored?

Your data is stored on secure servers hosted in Canada. All data at rest is encrypted with AES-256 encryption, and we maintain regular encrypted backups. Your client information never leaves Canadian jurisdiction unless you explicitly choose to export it.

Who can access my client data?

Only authorized users within your firm can access your client data, based on their assigned role (Admin, Manager, Staff, or ReadOnly). MyCPACRM support staff do not have access to your client data. Our architecture ensures complete isolation between offices, and all access is protected by two-factor authentication.

What happens if I cancel my subscription?

If you cancel, you will have a grace period to export all your data in standard formats (CSV, PDF). After the grace period, your data is securely deleted from our servers and backups in accordance with our data retention policy. We provide clear instructions and tools to ensure a smooth transition.

Do you sell or share client data?

Absolutely not. We will never sell, share, rent, or trade your client data to any third party. Your data is yours. We only process it as necessary to provide the MyCPACRM service to your firm, and we are fully transparent about our data practices in our Privacy Policy.

Your Security Matters

Questions About Security?

We're happy to discuss our security measures in detail. Reach out to learn how MyCPACRM keeps your firm's data safe.