How access to your work is controlled · security and trust
How access to your work is controlled
Will Pickeral, William Belle LLC · willpickeral@williambelle.co
For the person at your firm who has to sign off on using an outside vendor.
Everything below is how the private client area at portal.williambelle.co behaves today. Where something is a deliberate limit rather than a feature, it says so: a review that only lists strengths is not worth reading.
Who can get in
Only addresses I have been told to add. There is no sign-up page. Somebody at your firm can reach your work when you tell me their address and I add it; until then, typing that address into the sign-in page does nothing.
There are no passwords. Signing in sends a six-digit code to the address on record. It works once, expires in ten minutes, and five wrong guesses spend it. Control of that mailbox is the proof, and it is re-proved every time somebody signs in rather than once when an account was created.
That has a consequence worth stating plainly: anyone who can read a person's email can sign in as them. That is true of any system with a password reset, but here it is the whole mechanism rather than a fallback, so mailbox security at your end matters. If your firm uses phishing-resistant sign-in for email, that protection carries through here.
Asking whether an address is on file tells you nothing. The answer is identical for an address I hold and one I have never seen, so the sign-in page cannot be used to find out who my clients are.
What one person can reach
Your work, and nothing of anyone else's. Which client a person belongs to is decided when I add them and is carried by their signed-in session. It is never read from the web address, so editing a URL does not reach another client's material. Every query is filtered by who is asking, in the same operation that fetches the record.
One address belongs to one firm. An address that already signs in for another client is refused rather than moved.
Documents are never public. Files are held in private storage with no public address and no shareable link, and every download is authorized at the moment it is requested rather than by a URL that could be forwarded. Storage keeps thirty days of soft-delete and previous versions.
The database has no public endpoint. It is reachable only from inside the private network the application runs in.
How long access lasts
| Signed in and using it | stays signed in for about a month |
| Away for longer than that | signs in again with a new code |
| However much it is used | never longer than three months |
Access can be stopped immediately. Stopping a person signs them out of every browser at once, not when their session happens to expire. When somebody leaves your firm, tell me and it takes effect on their next click. Their colleagues are unaffected.
Taking a whole client off my active list stops everyone there at once.
What is recorded
Every one of these, with who, when, from what address, and what was touched:
- somebody signing in, and every change to who is allowed to
- every document opened or downloaded, by your people and by me
- a quote accepted or declined
- a file sent in
- an attempt to reach something that was refused
The record cannot be edited or deleted, and that is enforced by the database rather than by my good intentions. The table refuses updates, deletions and truncation outright, for every account including my own. Removing an entry means first disabling that rule deliberately, which is itself the point: it cannot happen by accident or in passing.
Each entry carries a fingerprint of the one before it. If any entry were altered or removed, the chain stops adding up at that point, and the page says so rather than waiting to be asked. You do not have to take that on trust: see the next section.
What you can ask me for
A record of every access to your material, for whatever period you name, as a spreadsheet or as a full export.
The full export carries the fingerprints, so your own people can check it has not been edited without needing access to my systems. That is the difference between a log that claims to be intact and one you can verify.
Ask at any time. There is no charge and nothing to arrange in advance.
What I do deliberately
I can read your documents. I am the person doing the work; a system where the person delivering it cannot open the files would not function. Every time I do, it is recorded in the same log you can ask for, against my name. There is no private path.
Payment details never reach this system. Invoices are paid on the payment provider's own pages. No card number touches it, and none is stored.
My own staff access is separated. Anyone working with me signs in through Microsoft Entra ID with a role that decides what they see. Somebody helping with sales cannot open your security findings or monthly reports; somebody helping with delivery cannot see anything about money.
Nothing about your work is sent anywhere else to be processed. It runs in Microsoft Azure and speaks to a payment provider and an email provider, both named in your agreement. There is no analytics service, no third-party script, and no advertising anything on the pages you use.
What this is not
Nothing here has been independently audited. The controls above are real and demonstrable, and the access log is built so that you can check it yourself rather than believe me. But no outside firm has reviewed the implementation, and I would rather you knew that than found out during a questionnaire.
No certification is claimed. Not SOC 2, not ISO 27001. If your firm requires one from its vendors, say so early and we will work out what that means for the project.
Asking about any of this
Write to willpickeral@williambelle.co. Questions from a client's IT or compliance people are answered directly, and I would rather have them before a project starts than after.