Your clients’ data, handled carefully

You are trusting us with other people’s tax records. The controls below are the ones that matter most for that, described plainly enough that you can check them against your own requirements.


Encryption in transit and at rest

Files move over TLS and are stored encrypted. Documents live in private storage that is never publicly addressable; access is granted through short-lived signed links rather than open URLs.


Access on a need-to-know basis

Staff see the engagements they are assigned to and nothing else. Access is granted deliberately by an administrator — a new account arrives able to see nothing at all.


Confidentiality agreements

Every person who touches client work is under a signed non-disclosure agreement, and we will sign yours as well as ours.


Identifiers kept to a minimum

We do not store full Social Security or taxpayer identification numbers. Where an identifier is needed for reference, only the last four digits are retained and displayed.


A permanent audit trail

Uploads, corrections, approvals and sign-offs are recorded with the person and the timestamp. Entries cannot be edited or deleted afterwards, by anyone, including us.


Controlled working environment

Client work happens on managed machines in a controlled office environment, not on personal laptops in uncontrolled locations.

What we deliberately do not do.

We do not contact your clients. We do not use client documents to train models. We do not run analytics or tracking that can see document content. And we do not keep working copies after an engagement closes.

Due diligence welcome

If your firm has a vendor security questionnaire, send it. We would rather answer forty questions up front than have you wondering later. If there is a control you need that we do not have yet, we will tell you that plainly rather than let it slide.

Send us your security questionnaire

We will complete it and come back with anything we cannot meet, before you commit to anything.