SECURITY

Your practice hands us client records, FICA documents and screening results. This is how that information is kept, and who can reach it.

Who can see what

Access is decided in two independent ways, and a user needs both to get to a record.

  • Every record belongs to exactly one organisation. Nothing is shared between practices.
  • Each user is granted a scope (organisation, branch, or just their own book) that sets how much of the practice's data they can see.
  • Every protected action requires a specific use case. Users hold use cases through roles, so access is granted once and reused rather than configured per person.
  • Client access can be narrowed further, so an adviser sees only the clients assigned to them.

A record of what happened

Advisory practices are asked to show their workings. The platform keeps that evidence as a by-product of normal use.

  • Changes made across the platform are written to an audit trail.
  • Compliance documents record who generated them, and which broker they speak for. The two are frequently different people, and both are kept.
  • Sanctions screening results are stored with the data that produced them, so a past decision can be explained later.

Client identity

Where a client signs a document themselves, the platform proves it was really them before the document ever opens.

  • Documents open only after a one-time PIN, sent by SMS to the cell number already on your client record. Forwarding the link to someone else does not get them in.
  • PIN requests expire, are rate limited, and lock out after repeated incorrect attempts.
  • Proof of a passed check is held by the client's browser for a bounded period. It is never something the client types, and so never something they can pass on.
  • A document that has already been signed cannot be signed a second time.

Where it runs

One Advisor is a hosted platform. You do not run servers, apply patches, or manage backups.

  • Hosted on Microsoft Azure.
  • Traffic between your browser and the platform is encrypted in transit.
  • Client documents are held in managed storage, and requests for them are checked against the requesting user's scope rather than trusted from the browser.

POPIA and your obligations

Your practice remains the responsible party for the client information it holds. The platform's job is to give you the controls to meet that responsibility.

  • Access scoping and use cases let you limit personal information to the people who need it.
  • The audit trail supports questions about who accessed or changed a record.
  • Client records, contacts and documents are held together, so a request about one client can be answered from one place.

Doing security due diligence on us? Email support@oneadvisor.net and we'll answer your questionnaire directly.

DEMO

If you are interested in One Advisor please let us know and we will contact you to set up a demo at your convenience