Encryption in transit and at rest
Files move over TLS and are stored encrypted. Documents live in private storage that is never publicly addressable; access is granted through short-lived signed links rather than open URLs.
Security
You are trusting us with other people’s tax records. The controls below are the ones that matter most for that, described plainly enough that you can check them against your own requirements.
Files move over TLS and are stored encrypted. Documents live in private storage that is never publicly addressable; access is granted through short-lived signed links rather than open URLs.
Staff see the engagements they are assigned to and nothing else. Access is granted deliberately by an administrator — a new account arrives able to see nothing at all.
Every person who touches client work is under a signed non-disclosure agreement, and we will sign yours as well as ours.
We do not store full Social Security or taxpayer identification numbers. Where an identifier is needed for reference, only the last four digits are retained and displayed.
Uploads, corrections, approvals and sign-offs are recorded with the person and the timestamp. Entries cannot be edited or deleted afterwards, by anyone, including us.
Client work happens on managed machines in a controlled office environment, not on personal laptops in uncontrolled locations.
We do not contact your clients. We do not use client documents to train models. We do not run analytics or tracking that can see document content. And we do not keep working copies after an engagement closes.
If your firm has a vendor security questionnaire, send it. We would rather answer forty questions up front than have you wondering later. If there is a control you need that we do not have yet, we will tell you that plainly rather than let it slide.
We will complete it and come back with anything we cannot meet, before you commit to anything.