5,300+ tax returns filed in the last 4 seasons — two-EA reviewed, on one platform. Talk to us

Security & compliance

Security, built in.

Our preparers and our preparers’ clients are on one ledger. The audit log we sell to firms is the audit log we use ourselves — encrypted at every layer, access controlled, and ISO 27001 certified.

§ Section I · Encryption

Encryption at every layer.

Documents are stored on AWS S3 with SSE-KMS. On The Practice and above you bring your own CMK on your own AWS account — we never see plaintext. TLS 1.3 in transit. Database encrypted at rest at the cluster level. Daily encrypted snapshots.

SSE-KMS · CMK

At rest

AWS S3 with SSE-KMS. Customer-managed key (CMK) available on The Practice and above; you control the key, we never see plaintext.

TLS 1.3

In transit

TLS 1.3 everywhere, including internal service-to-service. HSTS preloaded.

Org-scoped

Database

PostgreSQL with at-rest encryption at the cluster level; per-tenant logical isolation enforced at the ORM layer.

PITR · 5min

Backups

Daily encrypted snapshots, 30-day retention. Point-in-time recovery to within 5 minutes on The Firm.

§ Section II · Access

Access, audited.

TOTP MFA is required for every user. Sessions are signed HttpOnly cookies — no JWT-in-localStorage. Seven roles share one database with org-scoping on every endpoint to prevent client-list fingerprinting.

Required

Multi-factor

TOTP-based, per user, with admin-resettable recovery codes. SAML / SSO on The Firm.

Hardened

Session model

Cross-subdomain cookies, signed and HttpOnly; idle timeout configurable per role. No JWT-in-localStorage.

7 · 1 DB

Role isolation

Seven roles, one database. Org-scoping on every endpoint — an attacker cannot fingerprint your client list.

ACL · presigned

Document access

Per-taxpayer ACL on every blob. Time-limited presigned URLs; never publicly listable.

§ Section III · Audit

Every move, on the record.

A tamper-evident, append-only log on every consequential action. Case assignments, transfers, stage moves, document uploads, downloads, e-signs, and 8879 submissions all carry actor + timestamp. Export to CSV / JSON for your own SOC 2 evidence.

Immutable

Action log

Every case assignment, transfer, stage move, document upload, download, e-sign, and 8879 submission is logged with actor and timestamp.

Self-serve

Export

CSV and JSON exports of the audit log scoped to your org, retainable indefinitely. Useful for your own SOC 2 evidence.

Append-only

Tamper-evident

Logs are append-only at the database layer; an attacker with DB access cannot redact past entries silently.

§ Section IV · Compliance

Compliance, shipped.

ISO 27001 certified and designed against IRS Pub 4557 and Pub 5708. Standard DPA for firms with EU clients. Data residency options on The Firm — US-east default, EU-west and APAC available.

Certified

ISO 27001

Information-security management certified to ISO/IEC 27001. Our controls are independently audited, not self-asserted.

Pub 4557 / 5708

IRS guidance

Aligns with IRS Publication 4557 (Safeguarding Taxpayer Data) and Pub 5708 (Creating a Written Information Security Plan).

EU · UK · GDPR

DPA

Standard data-processing agreement for firms with EU clients on FBAR / streamlined filings. Sub-processor list maintained publicly.

us-east-1

Data residency

US-east by default. EU-west and APAC residency on The Firm.

§ Certifications

Independently verified.

Audited, not self-asserted
ISO/IEC 27001 information-security certified
ISO 27001 certified
IRS Enrolled Agents
IRS Enrolled Agents
GDPR compliant
GDPR compliant
“If we filed it, the platform recorded it — with our initials. The audit log we sell to firms is the audit log we use ourselves.”

— TaxSQR Security Note · May 2026