What we access — and what we never touch
FirmProof reads the same public web pages any visitor can. This page sets out exactly what that means in practice, so you can forward it to whoever signs things off — an office manager or an IT security team.
Sources last verified: 2026-08-14.1 — official SRA links are cited in each section.
What FirmProof reads
- Public pages of your website only — the pages any member of the public can open. We respect robots.txt by default and crawl politely (a few requests per second, like a search engine).
- We never sign in, submit forms, or bypass anything. Client portals, intranets and anything behind a login are invisible to us by design.
- No client data, ever. We monitor your marketing website, not your practice. Nothing we process is confidential or privileged material.
- Evidence we keep — page excerpts and screenshots — is stored privately against your account and shown only to your signed-in users. It is deleted automatically once it passes your plan's evidence window (12 months, 3 years or 6 years).
How the AI review works
On customer scans, an AI model (Anthropic's Claude) re-reads the public page text behind certain findings to reduce false alarms. It is deliberately constrained:
- It sees public page text and our detector's findings — nothing else.
- It can soften a finding, or confirm a check as clear only with a verbatim quote we verify against the page. It can never invent a problem.
- It never runs on the free public preview, and it is disclosed in our methodology and privacy policy.
Suppliers who process data
FirmProof runs on a small set of established providers:
| Cloudflare | Hosting, crawling infrastructure, bot protection and PDF/screenshot rendering |
| Supabase | Database, authentication and evidence file storage |
| Anthropic | AI review of findings on customer scans (public page text only) |
| Stripe | Payments — card details never touch FirmProof |
| Resend | Email delivery (digests, alerts, support) |
| Plausible | Privacy-friendly, cookieless website analytics |
Full processing detail, retention periods and your rights are in the privacy policy and data processing addendum.
Sensible security, honestly stated
- All traffic is HTTPS with HSTS; security headers (CSP, frame-ancestors) are enforced site-wide.
- Sessions use httpOnly cookies; sign-in is via Google, Microsoft or email with strong-password rules. Firm ownership is verified before any scan runs.
- Payment details are handled entirely by Stripe.
- Codable Labs Limited (the company behind FirmProof) is registered with the UK Information Commissioner's Office as a data controller — ICO registration ZC223489.
- We are a small, founder-run company. We don't yet hold ISO 27001 or SOC 2 certification — if your procurement process needs a questionnaire completed instead, email us and we'll complete it.
Vendor continuity — the small-supplier questions, answered
FirmProof is run by a named founder, and we'd rather answer the questions that raises than hope nobody asks them:
- Your data is exportable at any time, self-service. Findings download as CSV and monitoring statements as PDF from your dashboard — your dated compliance trail lives in files you hold, not only in our database. Nothing about your history is hostage to our continued existence.
- If we ever wound down, customers would get advance notice, a final export window, prorated refunds of prepaid fees, and deletion of remaining data — the same deletion commitments as in our data processing terms.
- No lock-in by design. Cancel any time; monitoring runs to the end of the period you've paid for, and your export rights survive cancellation until deletion.
- The dependency risk is bounded by what we do. FirmProof monitors and evidences — it doesn't host your website, hold your client data, or sit in any workflow that stops working if we do. Losing your monitor is an inconvenience, never an outage.
Questions your reviewer wants answered?
Forward this page, or send us the questionnaire — a real person replies within one working day.
Contact us