Compliance, security and chain of custody

Custody you can evidence. Records that cannot be quietly changed.

Firearmdesk is built as a system of record. This page describes the controls in the software today, in plain terms, so that a firm can satisfy itself before it refers.

Chain of custody

From the executor's hands to the closure pack.

Licensed sites only

Firearms are held only at licensed custody sites: dealers whose dealer licence and storage approval are recorded with expiry dates. A site with a lapsed credential cannot be allocated new work. The firm is told the custody region and when custody is confirmed; the site's identity is not disclosed outside the site and platform operations.

Receipted on arrival

At receipt each firearm is verified against the pre-advice, photographed, given an asset tag and receipted. Anything that does not match becomes an exception with a reasoned outcome, never a quiet edit.

Every movement recorded

Collection or handover, relocations within a site and releases are all custody events with a named person and a time. Internal storage positions and site addresses never leave the custody site's own screens.

Release under dual control

A release needs a signed executor instruction, a completed gate checklist, identity confirmed at retrieval and a second person's approval. Payment status never triggers release or disposal.

Stocktakes with frozen expectations

Periodic stocktakes compare the physical count with an expectation frozen at the start; discrepancies go to a reviewer who was not the counter.

A closure pack for the file

Receipts, photographs, the valuation, the signed instruction, the evidence of the sale or transfer and the settlement statement are filed together when the matter closes, and retained under the retention schedule.

Records and audit

Append-only, by design and by database.

  • Nothing is deletedFirearms, custody events, financial records, legal-rule history and audit events cannot be hard-deleted. Corrections are superseding records with a reason.
  • Every material write is auditedWho, what, when, the object and a before-and-after summary are recorded in the same transaction as the change.
  • Administrators cannot edit historyDatabase triggers enforce the rules, so no administrator can rewrite the audit trail through the application.
  • Status wording is controlledUsers see plain-language status; internal codes are never exposed.
Information security

Scoped, scanned, short-lived.

  • Tenant and matter scopingEvery query is scoped server-side to the firm and matter; a firm cannot see another firm's matter by guessing an identifier.
  • Two-factor verificationRequired for privileged and custody roles, with step-up verification for dual-control actions.
  • Malware scanning before viewingEvery uploaded document and photograph is scanned; nothing can be opened until it is recorded as clean.
  • Signed, expiring document linksDocuments are served through short-lived signed links; storage is private and never public.
  • Nothing sensitive by emailNotifications are rendered from templates that reject serial numbers, identity numbers and document content.
Hosting, retention and testing

Where the information is, how long it is kept, and what has been tested.

Hosting

The platform, its database, document storage and email run on a dedicated server operated by Hetzner Online GmbH in Helsinki, Finland, which is subject to the EU General Data Protection Regulation. The cross-border basis is set out in section 6 of the privacy notice.

Encryption

Traffic to the site and the portal is encrypted in transit with TLS, and outgoing email is sent over TLS. Document storage is private and reached only through short-lived signed links. Encryption of the database and document store at rest is being added with the backup service and will be stated here, with the date, once it is in place.

Retention

Matter records, custody events, invoices and the audit trail are kept for at least five years after a matter closes, and ten years where the matter had exceptions, waivers or a legal hold. Nothing is deleted early. Counsel is settling the final schedule, which will be published in the privacy notice.

Independent testing

An external penetration test will be commissioned before broad rollout. The tester, the date and a summary of the findings and their fixes will be published here. Until then the controls on this page are as built and have not been independently tested.

Legal position as configuration

Regulated steps default to no.

Whether a regulated action may proceed, such as receiving a firearm into dealer custody, is decided by a legal rule version proposed with its source, approved by two people and activated by compliance. Until a rule is active, the step waits. If a later order changes the position, a new version pauses the affected matters and tells the firms concerned.

Current legal status

Published and still to come

The privacy notice, terms of service and contact and complaints pages are published as interim versions pending counsel's review. The PAIA manual, retention schedule, insurance statement and the results of an external penetration test are still to come (as at 23 September 2026). The controls described on this page are as built and have not yet been independently tested. We do not make claims here that are not in place.

Ready when a firearm appears on the inventory.

A referral needs only the details you already have. We take it from there.