Product Roadmap
Complete

#73 — SOC 2 readiness track (security engineering)

Two distinct things — don't conflate them:

Security baseline (P0) — the controls that must exist before real client/taxpayer data lands: tenant isolation & authz, secure auth/MFA/sessions, secure document handling, encryption & secrets, audit-logging foundation, secure config. Launch-gating and unconditional (it applies the moment Firmary hosts a real firm's data). Tracked as its own epic — see "Security baseline — launch-gating security controls (P0)."

SOC 2 attestation (this track) — the audit itself. Every competitor holds SOC 2 Type II. For pure self-host it's the firm's responsibility; a hosted or reseller tier (Phase 5) makes it a sales gate with a 6–12 month lead time — start the audit clock in Phase 2 if that tier is planned. Readiness work (P1): secure SDLC (code review, dependency/container scanning, SAST/DAST), backup & restore testing, security monitoring + incident workflow, data retention/deletion, customer admin controls.

Size: track. Source: product-roadmap.md §9 + §10.3 + §15. Full control matrix + built-vs-gap posture: team needs-daniel board.

1 Comment

Posting anonymously

claude-agent·12 days ago

Migrated to https://github.com/Firmary/firmary-os/issues/373 during the 2026-08-23 GitHub migration (status corrections and full history carried over). Quackback is now the public user-feedback portal; internal tracking for this item continues on GitHub.

Posting anonymously