Security

Security starts with narrow access and honest boundaries.

Viewward handles financial records, so the service should be judged by what is implemented—not by broad promises.

Independent security review required before launch

Current safeguards

  • Passwordless email authentication for workspace access.
  • Private database and file-storage rules scoped to workspace membership.
  • Short-lived links for authorized file downloads.
  • Server-side checks for supported application actions and basic file validation.
  • Security headers, audit-event foundations, and private-by-default workspace creation.

Important security boundaries

No internet service can promise absolute security. Viewward’s authorization, file-upload, session, audit, retention, deletion, incident-response, and recovery controls require additional production validation. Multi-factor authentication and a third-party security assessment are also launch gates for broader use.

Do not upload high-risk identifiers

Until the sensitive-document review is complete, do not upload unredacted W-9s, Social Security cards, driver’s licenses, bank credentials, or documents containing full SSNs/TINs. Keep independent copies of all source records.

Your part

  • Protect the email account used for sign-in and enable MFA with your email provider.
  • Invite only trusted collaborators and verify the recipient address and role.
  • Remove unnecessary sensitive details before uploading a document.
  • Sign out on shared devices and report unexpected access promptly.

Report a security issue

Email security@viewward.com with a concise description and safe reproduction steps. Do not include real customer records, credentials, or sensitive identifiers in the report. For account help, use the support page.