Security

How 1folder data is protected

The public site currently collects bookkeeping inquiry details. Authenticated product surfaces are gated for existing, internal, or invited users while public access stays closed.

Public inquiry data is limited

The public flow asks for contact information and business context needed to plan an immediate start or waitlist placement. Do not submit sensitive financial documents through the public form.

Encrypted transport and managed storage

Browser traffic uses HTTPS. Application data is stored with managed providers such as Supabase and Vercel, with encrypted transport, managed infrastructure controls, and provider-level storage protections.

Authenticated surfaces are gated

Login, dashboard, onboarding, reporting, and admin areas require authentication or private network access. Existing/internal users can still sign in, but public visitors cannot self-serve into the product or checkout.

Invitation-only access is intentionally narrow

If a user is invited to share business records, access is limited to the team members needed to run or support the workflow. Admin routes are kept off the public host through the app proxy and private network routing.

Two-factor authentication

Authenticated users should enable 2FA from account security when available. It reduces the risk that an email compromise becomes an account compromise.

Set up at /account/security.

What happens if something goes wrong

If we discover a security incident affecting inquiry or authenticated data, we will investigate, contain it, and notify affected users as required by law.

What you can do

  • Use a unique email address for authenticated 1folder access.
  • Turn on 2FA when you have an account.
  • Do not paste sensitive financial records into the public form.
  • If your device or account is compromised, email [email protected].
Questions or concerns? [email protected].