Security
Last updated: July 1, 2026
Renshi CodaraFlow is built with security fundamentals chosen for sensitive tax and corporate data. It comes two ways, both billed monthly. With the managed offering, 1000149725 Ontario Inc. hosts and operates a dedicated instance for your firm in Canada and may access your data, under a data processing agreement, only to run and support the service. With the self-hosted offering, your firm runs the software on its own infrastructure and 1000149725 Ontario Inc. never hosts, operates, or accesses the running instance. This page describes the controls the software provides and the choices that remain with the firm under each model.
Where Your Data Lives
In a single database file dedicated to your firm. On the managed offering it lives on a dedicated instance we run in Canada, one firm per instance and per database, never combined with other firms’ records. On the self-hosted offering it lives on infrastructure your firm controls: a server inside your own network, or your firm’s own cloud account. Either way the data is a single database file, never spread across a shared multi-firm store.
Encryption
Connections are served over HTTPS. At rest, the managed instance keeps its database on an encrypted persistent volume in Canada. On a self-hosted install the firm controls encryption because the firm controls the host: use full-disk encryption on your own server (BitLocker, LUKS, or FileVault), or rely on the encrypted persistent volume your cloud provider gives a cloud instance. The database file itself is a standard, portable file, so it is never locked into a proprietary or vendor-held format.
Backups and Recovery
The admin Backup page produces a consistent snapshot of the database at any time, without stopping the app, as a single file. On a managed instance we take and retain encrypted backups in Canada and you can download a snapshot yourself at any time. On a self-hosted install the firm keeps the snapshot under its own backup policy. The entire persistent state is that one database file plus any uploaded templates, so recovery is to restore the file and restart.
Access Controls
- Two-factor authentication. Firms can require an authenticator-app code in addition to a password for every user.
- Brute-force protection. Repeated failed sign-ins lock an account for a cool-off period.
- Email-domain restriction.Only addresses on the firm’s own email domains can be added as users or sign in.
- Single active session. A new sign-in ends older sessions for that account.
- Audit log.Key actions are recorded so the firm can see who did what and when, including administrators’ own actions.
Incident Response
The audit log gives the firm the record of authentication events and data changes it needs to investigate and to meet its obligations to clients and regulators. On a self-hosted install, incident response is the firm’s own, on infrastructure the firm controls. On a managed instance, we operate the hosting and coordinate with the firm under the data processing agreement. If a security issue is found in the software itself, report it to us and, if it is real and material, we will issue a patched build.
Questions
For security questions, email us at [email protected].