Authentication and access requirements for firm users of RecordsFlow.
These terms form part of the RecordsFlow Services Agreement between RecordsFlow LLC and the subscribing firm (“Firm”), and are in addition to the Business Associate Agreement between the parties. “Authorized User” means an individual Firm permits to access the Services.
Firm shall ensure that every Authorized User accesses the Services using multi-factor authentication. RecordsFlow enforces multi-factor authentication on all accounts and does not offer an exception process.
RecordsFlow supports text-message codes as second factors.
Each set of credentials is issued to one named individual. Firm shall not permit Authorized Users to share credentials, and shall not create shared, generic, or role-based accounts.
Firm is responsible for all activity occurring under its Authorized Users’ credentials.
Firm shall disable an Authorized User’s access within 24 hours of that person no longer requiring it, including on termination of employment or engagement.
Firm shall notify RecordsFlow at security@recordsflow.com within 24 hours of discovering that any credential used to access the Services has been, or may have been, compromised.
This obligation is separate from, and runs ahead of, any breach-notification obligation under the Business Associate Agreement. A compromised credential is not yet a breach, and RecordsFlow needs to know before it becomes one.
RecordsFlow may suspend an Authorized User’s access, or Firm’s access, without prior notice where it reasonably believes credentials have been compromised. RecordsFlow will notify Firm as promptly as practicable and will restore access once the matter is resolved.
RecordsFlow will verify the identity of any person requesting a credential reset or a change to an authentication method before acting on the request, and may decline a request it cannot verify.
As between the parties, Firm is responsible for access obtained using its Authorized Users’ credentials, including access resulting from a failure to deprovision an Authorized User or from the sharing of credentials. This does not limit RecordsFlow’s responsibility for a failure of the authentication controls RecordsFlow operates.
RecordsFlow may change the authentication methods it supports, including by discontinuing a method that is no longer consistent with applicable standards, on 30 days’ notice to Firm. Firm shall implement any changes required of it within that period.
Email security@recordsflow.com or call 503-400-6877.