Security

You are holding other people's tax logins. That deserves care.

A tax practice keeps the keys to its clients' financial lives. FileDesk is built on that assumption rather than adding security afterwards. Here is what we protect and how, in everyday words.

Client logins

How a client's portal password is kept safe

Locked before it is saved

Every portal username, password and PIN is encrypted the moment it is saved. Anyone looking at the stored records sees scrambled text, not passwords.

Each part locked separately

The username, the password and the PIN are each encrypted with their own key, rather than all sharing one.

Never shown in passing

Saved passwords never appear in FileDesk's own logs or in the live updates it sends between screens, and they are left out of ordinary client lists. They go only to a signed-in, approved extension that asks for them over an encrypted connection.

Locked again on the computer

The branch's extension stores them again under a key that belongs to that one installation and cannot be copied out of it. It unlocks a password only at the moment someone asks FileDesk to fill a login form, and never keeps an unlocked copy.

The master key that protects all of this is kept apart from the stored records and is never part of FileDesk's code.

Client documents

Scanned on your phone, encrypted before it leaves

Scanned on your device

Finding the page edges, straightening and cleaning up a scan all happen on your own phone or computer. Scans and documents are never sent to any AI service.

Encrypted before upload

Each document is encrypted on your device, with its own key, before it is uploaded. Our storage provider only ever holds the encrypted file and never has a key to open it.

Opened only with permission

A document's key is given only to signed-in staff who are allowed to view documents, and every time someone opens a document it is written in the activity log.

Deleted means deleted

Deleting a document removes its key straight away, so it can no longer be opened. The encrypted file is then removed from storage, with automatic retries until the removal is confirmed.

Separation

One agency can never see another

Every request is checked against the agency of the person signed in — never against anything their browser claims. An automated test suite proves it by having one agency try to reach another agency's real records.

Checked every time

Clients, cases, payments and saved passwords are always looked up inside your own agency. Ask for another agency's record and FileDesk answers "not found" — it does not even confirm the record exists.

Changes refused too

Editing a client, saving a password, closing a case, resetting a branch password: tried across agencies, every one is refused.

Roles checked by FileDesk

A branch cannot reach owner-only pages even by typing the address. Hiding a button is never the only protection.

Access

Who is signed in, on what, right now

FileDesk settings screen with agency account and extension access controls
Account and extension controls are visible to the agency owner without exposing client credentials.

Your own password, stored one-way

Account passwords are stored only in a scrambled, one-way form that cannot be turned back into the password. A failed sign-in never reveals whether the username exists.

Two web devices, one extension

An ordinary account can stay signed in to the web app on two devices at once, such as a phone and a desktop, and has one active extension. A third web sign-in ends the least recently used one — shared logins become visible instead of silent.

Approved computers only

The extension works only on a computer the agency has approved — one per account. Moving to a new computer means the old one is revoked and the new one approved.

Guessing is slowed down

After repeated wrong passwords, sign-in is paused for that account and that connection, and the message never says which part was wrong.

The extension

Deliberately small

Only the portals it is built for

It works only on the specific FBR portal pages it is built for — never on every website you visit. Adding a portal needs a new version of the extension.

Two fields, never the CAPTCHA

It fills the username and the password. It will not touch a CAPTCHA or a one-time code, and refuses if asked to.

Prepared for Chrome Web Store review

It talks only to FileDesk and the supported FBR pages. A FileDesk account, licence and approved installation are still required once it is listed on the Chrome Web Store.

Your data

Where it lives, and how it comes back

Kept apart from other agencies

Each agency's records are kept separate from every other agency's, and automated tests check that separation.

Encrypted backups

Backups are made on a schedule and encrypted, and the key that opens them is kept offline, away from FileDesk — so a stolen backup is useless to whoever took it. Backups never contain client documents.

Nothing sold or used for advertising

Client data is not sold or used for personalized advertising. The website you are reading loads no third-party scripts and sets no cookies.

Deactivate, don't delete

Clients are deactivated so financial history stays intact, while saved portal passwords can be removed at any time without touching that history.

Want the detail?

Ask us anything about how FileDesk protects your clients' data. Technical questions get technical answers.