Trust & Security

Your data, protected end-to-end.

This page is maintained by FRM Chartered Accountants to answer common security and privacy questions about the FRM client portal. It describes controls currently enabled — it is not an independent certification.

Encryption in transit & at rest

All traffic to frmca.org is served over HTTPS with valid TLS certificates. Data is stored in an encrypted managed database, and file attachments are held in encrypted object storage accessed via time-limited signed URLs.

Authentication

Sign-in supports email + password and Google. Passwords are hashed with industry-standard algorithms and screened against the Have I Been Pwned breached-password list; known-compromised passwords are rejected at sign-up and password change.

Inactive sessions are automatically signed out after 30 minutes.

Access control

Every client-facing table uses row-level security so users can only read and write their own records. Staff roles (admin, accountant, auditor) are stored in a separate roles table and checked through a hardened has_role() function to prevent privilege escalation.

Auditing

Sensitive actions — sign-ins, admin operations, document access, financial writes — are recorded in an append-only audit log reviewable by administrators.

Hosting & platform

The FRM portal runs on Lovable's managed cloud infrastructure: an edge network for the web app and a managed database, authentication and storage tier for the backend. We rely on our platform's underlying SOC 2 Type 2–certified providers for physical and network security.

Incident response

If we become aware of a security incident that affects your data, we will notify affected clients without undue delay and describe the impact, our response, and any steps you should take.

Report a suspected vulnerability to info@frm-ca.co.zw.

Shared responsibility

Security is a partnership. FRM operates the platform controls above. As a user, please help by using a strong unique password, keeping your device and browser up to date, signing out on shared computers, and reporting anything suspicious. FRM staff will never ask for your password.