Skip to content
Cranston

How Cranston keeps firm and client data safe

CPA firms trust Cranston with client books, tax documents, and firm workflows. These are the safeguards and controls behind that trust.

SOC 2TYPE II

SOC 2 Type II

Examination in progress

Enterprise controls

Encryption, RBAC, audit logs, SSO

GLBA

GLBA

IRS Pub. 4557 safeguards

Three safeguards, across every workflow

Every control on this page supports one of them.

Privacy

Each firm works in its own workspace

No other firm can see your client data, processes, or skills in Cranston. Client data is never shared across customers.

Encryption

Encryption across the platform

All data is encrypted: AES-256 at rest, TLS in transit. Point-in-time backups protect against data loss.

Review

Your reviewers approve everything

Nothing posts to a client ledger or goes out for filing without your reviewer’s approval. Every number links back to its source document, so reviewers can see the page behind it.

Enterprise security controls

The controls behind the safeguards. Talk to a founder to review each one with your team.

One firm, one workspace

No other customer can see your client data, workflows, or firm-specific skills.

AES-256 at rest

Files, returns, and ledgers are encrypted at rest across the platform.

TLS in transit

Every connection between your firm and Cranston is encrypted in transit.

Role-based access & SSO

Role-based access across the platform, with SSO for your team.

Audit logs

Every action across the platform is logged for review.

PII protection

Personally identifiable information is protected across the platform.

Point-in-time backups

Point-in-time backups protect your firm’s workspace.

Source-linked outputs

Every figure links back to its source document.

Security questions, answered

No. Each firm works in its own workspace. No other Cranston customer can see your client data, workflows, or firm-specific skills, and client data is never shared across customers.

Transform the way your firm operates