Animated backdrop: hundreds of the documents, messages, missed calls, invoices, and IRS notices a firm chases tumble in a storm around an old stone shell. The papers strike it, the stone cracks and falls away, and the calm staff queue that was underneath absorbs the whole day — each item posting as a row in a single living record.
Run the firm.
Stop chasing it.
Portal, documents, e‑sign, billing, and the staff queue for accounting firms: one record for both sides, updated the moment anything happens.
One email when your invite is ready. Nothing else.
The whole day, posted to one record · fictional data
Every page finds its place.
Your client sees a portal. Your team sees a queue. It’s one record.
Client · Meridian West LLC · demo data
2025 K-1 statements
Uploaded · scanned clean
Engagement letter
Signed
Year-end questionnaire
12 of 20 answered
Invoice 1042
Paid
Everything current · updated 4:56 PM
document.uploaded
Firm · Hollis & Marsh
Review K-1 upload
In queue · just now
Engagement 041
Active · letter filed
Review responses
Waiting on client
Q2 bookkeeping
Posted · books current
6 in queue · 2 assigned
Built inside a CPA firm that tried everything else first.
Firmary didn’t begin as a software company’s theory of how firms work. It began inside a working CPA firm: a practice run across a portal tool, an e‑sign tool, a scheduler, a billing system, and the email that held them together, where every seam showed up as a real missed handoff with a real client attached.
So we shopped. We tried the practice-management tools on the market, all of them, and every one made the same offer: adopt its workflow and lose your own, or keep your own and live with the seams. Nothing fit a firm that knew exactly how it wanted to run.
So we built the system we couldn’t buy, from the owner’s chair rather than the vendor’s. Firmary is that system.
Five tools · every hand-off is a wire
Portal tool
re-uploads
E-sign tool
names copy-pasted
where things got lost
Scheduler
separate login
Billing system
status by hand
× ten hand-offs, no shared record
Firmary · five modules, one record, zero wires
Settings, not a consulting engagement.
Every practice runs differently, so Firmary is configured, not customized: switch modules on per firm, start from onboarding blueprints for your firm type, and shape templates and client fields to your operating model, in an afternoon rather than an implementation project.
Onboarding blueprintsBy firm type
TemplatesEmail · letters · forms
Client fields & tagsYours to define
Try the part your clients will talk about.
You’re the client. Clear the phone in any order: upload, sign, pay, book, reply. Each moment lands on your side already filed, assigned, and current. No one forwards anything.
You’re the client
You’re also the firm · click around
…
Everything the client touches posts straight to your queue. It runs both ways: open Documents on the firm side and request one.
Nothing moves unauthorized. Nothing happens off the record.
Firmary carries tax documents, financial statements, and signatures: the most sensitive things a firm holds. So security is baseline architecture, not late hardening, and the posture reads like architecture:
09:31:04document.uploaded2025 K-1srecorded
09:31:22scan.completedcleanrecorded
11:12:47signature.completedletter 041recorded
13:40:11authz_denyout-of-scope readblocked
16:56:20payment.succeededinvoice 1042recorded
Retained 7 years · CPA baseline
- UploadsScanned before anyone can touch them
- Every file is malware-scanned on upload and isn’t downloadable until it passes. Infected files are quarantined; that path is drilled in production with live test malware, not assumed.
- AccessSigned links that expire in minutes
- Files are served through signed URLs scoped to one file and one authorized person, with a lifetime measured in minutes. No public buckets, ever.
- TenancyFirms are hard boundaries
- Every read and write is authorized server-side against your firm’s boundary, deny by default, and cross-tenant isolation is exercised by the test suite on every change.
- AuditAppend-only, kept seven years
- Access changes, signatures, payments, exports, configuration: every sensitive action lands in an append-only audit log retained to the CPA baseline.
- Sign-inStandards-based, with MFA
- OpenID Connect sign-in with multi-factor for staff. Sign-in and invitation endpoints are rate-limited, and the limiter fails closed.
- SecretsEncrypted at rest, held minimally
- Per-firm integration credentials are encrypted with AES-256-GCM. Card data never touches Firmary; Stripe is the system of record for payment.
No SOC 2 badge yet: Firmary is pre-launch. Internal security-review gates and automated secret scanning run on every change; a third-party audit comes before general availability. We’d rather say that plainly than imply otherwise. The full posture →
Your data is yours.
The exits are built in.
The interface is thin on purpose: every workflow runs through one module API that owns validation, permissions, tenancy, and audit. The portal is just that API’s first consumer, so opening the same surface to your own tools isn’t a favor; it’s the design. Each surface below is labeled with what it is today.
Consumers · every one equal
One door
- Firmary · portal & staff surfacesRUNNINGThe first consumer, with no privileged path. The interface calls the same API anything else would.
- Your custom appsBUILTEmbed your own tools inside the portal and staff shell: short-lived, tightly scoped tokens, allow-listed per firm.
- REST API + webhooksIN DESIGNVersioned, with generated OpenAPI. The goal on record: every workflow the interface completes, completable headless.
- MCP · your AI agentsIN DESIGNConnect Claude, ChatGPT, or your own agents, under your roles, on your audit trail, never above them.
One module API
The only door to your data
AuthorizationDeny by default
TenancyYour firm only
AuditEvery call, every caller
Behind it: your firm’s record, with an audited export path in the data model since day one.
Consumers · every one equal
- Firmary · portal & staff surfacesRUNNINGThe first consumer, with no privileged path. The interface calls the same API anything else would.
- Your custom appsBUILTEmbed your own tools inside the portal and staff shell: short-lived, tightly scoped tokens, allow-listed per firm.
- REST API + webhooksIN DESIGNVersioned, with generated OpenAPI. The goal on record: every workflow the interface completes, completable headless.
- MCP · your AI agentsIN DESIGNConnect Claude, ChatGPT, or your own agents, under your roles, on your audit trail, never above them.
One door
One module API
The only door to your data
AuthorizationDeny by default
TenancyYour firm only
AuditEvery call, every caller
Behind it: your firm’s record, with an audited export path in the data model since day one.
And if you ever leave, leaving is an export, not a negotiation: the audited export-then-delete path has been part of the data model since the first migration.
Clients sign in to your firm, not to Firmary.
Your logo, your colors, your domain: through the portal, the notification emails, and the sign-in screen itself. Firmary runs the machinery; the client relationship stays yours, under your name.
Sign in to your client portal
maya@meridianwest.com
Continue
Who sees which clients is yours to define.
Build custom roles from granular capabilities, scope staff to client segments, and let the server enforce every decision: denied by default, written to the audit log when it matters.
Documentsread & upload
Tasksassigned only
Billingno access
Client visibilitysegment · 1040 clients
Denied by default · every grant audited
Premium attention, without the premium headcount.
Every firm is told to pick a lane: boutique and capacity-capped, or scaled and impersonal. Most software quietly enforces that trade: it makes people faster at chasing without making the firm calmer as it grows. Firmary is built to refuse it. Both columns, in balance:
The promise
How it’s kept
Clients stop chasing you for status
The portal shows everything current the moment it happens, so the “just checking in” email has nothing left to ask.
Your team stops wondering what’s next
Every client action posts straight into the work queue: assigned, ordered, and already carrying its context.
Nothing lives in one person’s head
One record holds every document, signature, invoice, and decision. The method survives busy season, and the audit trail writes itself.
You grow the book, not the chaos
Automations carry the routine so your people carry the judgment. More clients per person is the design goal, not the marketing line.
New clients feel it on day one
Onboarding blueprints, a template library, and CSV import make setup an afternoon. The first impression is a working portal, not a PDF packet.
AI arrives on your termsThe road ahead
When your firm brings agents to the work, they’ll come through the same door as everything else: your roles, your audit trail, your say. The architecture already assumes it.
If you run a small or mid-size firm and intend to feel small to every client while carrying a book that used to take twice the people, Firmary is being built for you, and with you.
Early means early.
Firmary is pre-launch. The system above is built and being proven on real work (live signatures, live payments, live document storage) before any firm depends on it. No invented customers, no invented numbers; just the work.
Early firms get a say in what ships next, and a reply from a human, not a ticket.