Built to be trusted with a firm's whole book.
Clerra holds tax documents and financial records for many firms and their clients. Security isn't a feature we added — it's the foundation everything else sits on.
Canadian data residency, by default
Your client records, documents and backups are stored in Canadian data centres (Montréal region). AI-assisted features — email triage and the in-app support assistant — are processed in the United States under zero-data-retention terms, and the optional Advanced AI upgrade uses a more capable US model. See our privacy policy for the categories of providers we use.
Firms are isolated at the database
Every row of data is locked to your firm by row-level security enforced inside the database itself — not just in application code. No bug, no misconfigured screen, no clever request can show one firm another firm's data.
Clients see only what's theirs
The client portal is a separate trust zone. A client sees their own document checklist and the files you've chosen to share — never your notes, your other clients, your team's workload or anything internal. We test these boundaries automatically.
Documents are never publicly addressable
Files live in private storage, scoped per firm and per client. Downloads happen through expiring signed links generated only after the database confirms the person is allowed to see that exact file. Uploads are validated by type and size.
Two-factor authentication, for staff and clients
Anyone — your team or your clients — can protect their account with an authenticator app. Once enabled, a password alone is never enough to get in.
Everything sensitive is on the record
Document access, uploads, deletions, invitations, permission changes — recorded in an activity log your firm's admins can review. When a client asks who touched their file, you have an answer.
Encrypted everywhere
Data is encrypted in transit (TLS) and at rest. Payment details never touch our servers — billing runs entirely through a dedicated third-party payment processor.
Least privilege, by default
Staff roles separate day-to-day work from administration. Billing, team management, client deletion and the audit trail are admin-only. Public sign-in pages are protected by CAPTCHA and rate limits.
Ready for your IT and procurement teams.
The controls a growing firm needs to standardize on Clerra — available on the Large plan.
Single sign-on (SSO / SAML)
Let your team sign in through your firm's identity provider. Available for larger firms.
Uptime SLA
A stated uptime commitment, in writing, for firms that require one.
Dedicated onboarding & migration
We import your client list from QuickBooks, Sage or a spreadsheet and get your whole team live.
Granular roles & audit trail
Role-based access across offices, with a complete firm-wide activity log for every action.
Security is the foundation, not a feature.
Data stored in Canada
Row-level firm isolation
Two-factor authentication
Full activity audit trail
Have a security question we haven't answered?
Write to security@commongoodlabs.ca — we answer these personally.
