Security
Practical safeguards for portal workflows.
How Fidara Group handles portal access, private document storage, time-limited downloads, and activity logging.
Portal Access
- Client portal access requires account login and a linked client account.
- Administrative portal actions require staff access controls through the portal profile role.
- Users are responsible for using strong passwords, keeping credentials private, and signing out on shared devices.
Documents
- Uploaded documents are stored in private Supabase Storage buckets rather than public website folders.
- Document downloads use time-limited signed links generated only after the portal verifies access.
- Archived documents are hidden from client views. Deleted document actions remove the physical storage file and retain metadata for audit history where possible.
Monitoring and Reporting
- Portal activity is logged for key client and admin events, including uploads, downloads, status changes, billing item changes, messages, archive actions, and delete actions.
- No website or portal can guarantee complete security. Fidara Group avoids overclaiming certification or compliance status from these controls alone.
- Contact Fidara Group promptly if you notice suspicious portal activity, unexpected reset emails, or possible credential exposure.