Confidentiality controls
Technical and operational controls that enforce our confidentiality commitments.
Privilege-First Architecture
Data ownership is firm-level by design. No FirmFirst employee accesses firm data without an explicit support ticket and your authorization.
End-to-End Encryption
AES-256 at rest and TLS 1.3 in transit. Even in the event of infrastructure compromise, your data is unreadable without your firm's keys.
No Advertising. No Data Brokering.
We don't run ads. We don't sell data. We don't share inquiry data with other firms, marketing companies, or data brokers — ever.
Full Deletion on Request
When you cancel or request deletion, all prospect data is permanently deleted within 30 days. You can also trigger immediate deletion from your dashboard.