Security & Trust

Your documents and data, protected by design.

Security at MyFinancialAdvisory: a private document vault, tenant isolation, least-privilege access, encryption in transit and audit logging — built into the platform, not bolted on.

Controls

The safeguards behind every account

Security is part of how the platform is built — here’s what protects your information.

Private document vault

Uploads are stored in private buckets and never exposed as public links. Raw storage paths are never shared.

Signed, expiring access

Files are served through short-lived signed links that expire — so access can’t be reused or shared indefinitely.

Tenant isolation

Row-level security ensures you can only read or change records for organisations you belong to. Cross-tenant access is denied by default.

Least-privilege access

Roles grant only what’s needed. Server-side access is scoped to specific tables and operations — never blanket access.

Encryption in transit

All traffic between your browser and the platform is encrypted over HTTPS, with established session and auth handling.

Audit logging

Sensitive actions, including document access and downloads, are recorded in append-only logs for accountability.

Server-side secrets

Privileged keys stay on the server and are never shipped to the browser, keeping the admin boundary protected.

Expert review

AI assists with checks, but qualified professionals review high-impact work before any filing is submitted.

How it flows

What happens to a document you upload

1

Upload

You upload a document from your portal over an encrypted connection.

2

Private vault

It’s stored in a private bucket tied to your organisation — no public URL is ever created.

3

Scoped access

Only permitted roles can open it, through a signed link that expires shortly after issue.

4

Audit trail

Each access and download is written to an append-only log you and we can rely on.

Shared responsibility

Security is a partnership

We protect the platform; a few simple habits on your side keep your account safe too.

  • Use a strong, unique password and never share it.
  • Invite only team members who need access, with the correct role.
  • Tell us immediately if you suspect unauthorised access to your account.

Found an issue?

We welcome responsible disclosure.

If you believe you’ve found a security vulnerability, email us with the details and we’ll work to address valid reports promptly.

info@myfinancialadvisory.com