Trust & security
What we access — and what we never touch
FirmProof reads the same public web pages any visitor can. This page sets out exactly what that means in practice, so you can forward it to whoever signs things off — an office manager or an IT security team.
Check your own site — free scanNo account needed · public pages only · one free scan a day
Sources last verified: 2026-08-14.1 — official SRA links are cited in each section.
What FirmProof reads
- Public pages of your website only — the pages any member of the public can open. We respect robots.txt by default and crawl politely (a few requests per second, like a search engine).
- We never sign in, submit forms, or bypass anything. Client portals, intranets and anything behind a login are invisible to us by design.
- No client data, ever. We monitor your marketing website, not your practice. Nothing we process is confidential or privileged material.
- Evidence we keep — page excerpts and screenshots — is stored privately against your account and shown only to your signed-in users.
How the AI review works
On customer scans, an AI model (Anthropic's Claude) re-reads the public page text behind certain findings to reduce false alarms. It is deliberately constrained:
- It sees public page text and our detector's findings — nothing else.
- It can soften a finding, or confirm a check as clear only with a verbatim quote we verify against the page. It can never invent a problem.
- It never runs on the free public preview, and it is disclosed in our methodology and privacy policy.
Suppliers who process data
FirmProof runs on a small set of established providers:
| Cloudflare | Hosting, crawling infrastructure, bot protection and PDF/screenshot rendering |
| Supabase | Database, authentication and evidence file storage |
| Anthropic | AI review of findings on customer scans (public page text only) |
| Stripe | Payments — card details never touch FirmProof |
| Resend | Email delivery (digests, alerts, support) |
| Plausible | Privacy-friendly, cookieless website analytics |
Full processing detail, retention periods and your rights are in the privacy policy and data processing addendum.
Sensible security, honestly stated
- All traffic is HTTPS with HSTS; security headers (CSP, frame-ancestors) are enforced site-wide.
- Sessions use httpOnly cookies; sign-in is via Google, Microsoft or email with strong-password rules. Firm ownership is verified before any scan runs.
- Payment details are handled entirely by Stripe.
- We are a small, founder-run company. We don't yet hold ISO 27001 or SOC 2 certification — if your procurement process needs a questionnaire completed instead, email us and we'll complete it.
Questions your reviewer wants answered?
Forward this page, or send us the questionnaire — a real person replies within one working day.
Contact us