Back to Security

Last Updated: September 11, 2026

Access Control Policy

Purpose

To ensure that access to client non-public personal information is limited to identified individuals with a business need, and that the limit is enforced by the system rather than by convention.

Scope

All Finpace personnel, all client firm users, and all end clients who access the platform through a form link.

1. Identity

Finpace does not store passwords. Authentication is by one of two means:

  • Email one-time code. Six digits, valid for ten minutes, invalidated on use. Sends are rate limited to five per recipient per ten-minute window to resist enumeration and mailbox flooding.
  • Single sign-on through the firm's own identity provider, where configured.

Because no password is stored, there is no password database to breach, and credential-stuffing attacks against reused passwords do not apply to Finpace accounts.

2. Multi-factor authentication

Time-based one-time password (TOTP) enrolment is available to every firm user and is recorded per user. A firm may operate in a required mode, in which a user who has not enrolled is blocked from the application after a defined grace period rather than merely warned.

Recovery from a lost authenticator is by an explicit reset request, recorded and actioned by an administrator. Factors are not removed silently.

3. Authorisation

Access is granted on two axes: a role, and a set of discrete capabilities. A user may hold more than one role.

  • firm_admin: Administers the firm, its users and its integrations
  • advisor: Works with their own clients and paperwork
  • compliance: Oversight and review across the firm
  • support: Operational assistance without client ownership

Capabilities are granted individually and independently of role, so a firm can grant exactly what a person needs:

  • can_view_all_customers: Seeing clients beyond those assigned to the user
  • can_fill_pdfs: Generating completed paperwork from stored client data
  • can_build_pdfs: Mapping and publishing PDF form templates
  • can_build_webforms: Authoring client-facing questionnaires
  • can_send_webforms_to_clients: Sending a form to an end client
  • can_request_documents: Requesting documents from an end client
  • can_connect_own_crm: Connecting a third-party CRM to the firm

Least privilege is the default. A newly invited user holds no capability until one is granted.

4. Enforcement

Authorisation is enforced by Row Level Security in the database, not by application code. Coverage is complete: 290 of 290 production tables, carrying 713 policies, verified 2026-09-11. A defect in the application cannot cause one firm's client records to be returned to another firm, because the query itself is constrained before it returns a row.

5. End-client access

An end client reaches only the single form they were sent. Access requires possession of an unguessable share link and, where the firm requires it, an emailed one-time code. Links carry an expiry which is checked on every request, and an expired link grants nothing.

6. Personnel access to production

Production database access is restricted to named Finpace engineering personnel and is used for operation and support of the service. Administrative access to a firm's data for support purposes is performed only at the firm's request. All changes to client records are written to the audit trail described in the Incident Response Plan regardless of who makes them.

7. Provisioning, review and revocation

Firm users are invited by a firm administrator. Finpace does not create firm users on a firm's behalf except during a supervised onboarding, at the firm's written request.

Access is reviewed at least annually, and on any change of personnel. Access is revoked on the same business day that a person's role ends. Revocation is immediate on removal of the user record; there is no cached credential to expire.

8. Exceptions

Any exception to this policy requires written approval from the ISMC Chair, must state an expiry date, and is reviewed at the next annual review.