Customer-Owned Records
The primary Fiduciary Journal™ ledger is created in or connected to the authorized user's Google Drive. This gives the user direct access to the underlying spreadsheet through their own Google account.
Google Authorization
The application uses Google's OAuth authorization process. Users review the permissions requested by the application before access is granted, and access may be revoked through Google Account security controls.
Scoped Application Use
Authorized Google access is used to support user-facing application functions such as identifying the correct workspace, provisioning or restoring the ledger, opening it for the user, and saving requested records.
Session and Request Protection
The production architecture uses signed application state and authenticated service requests to associate provisioning and journal operations with the correct authorized user session.
Transport Security
Production website and application traffic is served over HTTPS. Security headers are configured to reduce common browser-based risks such as framing, content-type confusion, and unnecessary permission access.
Operational Safeguards
Operational logging and diagnostics may be used to investigate errors, detect misuse, and maintain service reliability. Access to production systems should be limited to authorized administrative purposes.
User Security Responsibilities
- Protect your Google account and use appropriate account security controls.
- Review authorization prompts before granting access.
- Do not share sensitive ledger information with unauthorized persons.
- Revoke application access if you believe your account or authorization is compromised.
Report a Security Concern
Send security concerns to admin@recordandremedy.com. Please include enough detail to help us investigate, but do not send passwords, access tokens, or other authentication secrets by email.