At rest
AWS S3 with SSE-KMS. Customer-managed key (CMK) available on The Practice and above; you control the key, we never see plaintext.
Our preparers and our preparers’ clients are on one ledger. The audit log we sell to firms is the audit log we use ourselves — encrypted at every layer, access controlled, and ISO 27001 certified.
Documents are stored on AWS S3 with SSE-KMS. On The Practice and above you bring your own CMK on your own AWS account — we never see plaintext. TLS 1.3 in transit. Database encrypted at rest at the cluster level. Daily encrypted snapshots.
AWS S3 with SSE-KMS. Customer-managed key (CMK) available on The Practice and above; you control the key, we never see plaintext.
TLS 1.3 everywhere, including internal service-to-service. HSTS preloaded.
PostgreSQL with at-rest encryption at the cluster level; per-tenant logical isolation enforced at the ORM layer.
Daily encrypted snapshots, 30-day retention. Point-in-time recovery to within 5 minutes on The Firm.
TOTP MFA is required for every user. Sessions are signed HttpOnly cookies — no JWT-in-localStorage. Seven roles share one database with org-scoping on every endpoint to prevent client-list fingerprinting.
TOTP-based, per user, with admin-resettable recovery codes. SAML / SSO on The Firm.
Cross-subdomain cookies, signed and HttpOnly; idle timeout configurable per role. No JWT-in-localStorage.
Seven roles, one database. Org-scoping on every endpoint — an attacker cannot fingerprint your client list.
Per-taxpayer ACL on every blob. Time-limited presigned URLs; never publicly listable.
A tamper-evident, append-only log on every consequential action. Case assignments, transfers, stage moves, document uploads, downloads, e-signs, and 8879 submissions all carry actor + timestamp. Export to CSV / JSON for your own SOC 2 evidence.
Every case assignment, transfer, stage move, document upload, download, e-sign, and 8879 submission is logged with actor and timestamp.
CSV and JSON exports of the audit log scoped to your org, retainable indefinitely. Useful for your own SOC 2 evidence.
Logs are append-only at the database layer; an attacker with DB access cannot redact past entries silently.
ISO 27001 certified and designed against IRS Pub 4557 and Pub 5708. Standard DPA for firms with EU clients. Data residency options on The Firm — US-east default, EU-west and APAC available.
Information-security management certified to ISO/IEC 27001. Our controls are independently audited, not self-asserted.
Aligns with IRS Publication 4557 (Safeguarding Taxpayer Data) and Pub 5708 (Creating a Written Information Security Plan).
Standard data-processing agreement for firms with EU clients on FBAR / streamlined filings. Sub-processor list maintained publicly.
US-east by default. EU-west and APAC residency on The Firm.



“If we filed it, the platform recorded it — with our initials. The audit log we sell to firms is the audit log we use ourselves.”
— TaxSQR Security Note · May 2026