5,300+ tax returns filed in the last 4 seasons — two-EA reviewed, on one platform. Talk to us →

Security & compliance

Security & compliance, built in.

Our preparers and our preparers’ clients are on one ledger. The audit log we sell to firms is the audit log we use ourselves — encrypted at every layer, access controlled, and ISO 27001 certified.

§ Section I · Encryption

Encryption at every layer.

Documents are stored on AWS S3 with SSE-KMS under a dedicated AWS KMS key, and Social Security numbers and other sensitive fields are encrypted again in the application. TLS 1.3 in transit. Database encrypted at rest at the cluster level. Daily encrypted snapshots.

SSE-KMS

At rest

AWS S3 with SSE-KMS under a dedicated AWS KMS key, enforced on every upload by bucket policy. Social Security numbers and other sensitive fields are also encrypted at the application layer.

TLS 1.3

In transit

TLS 1.3 everywhere, including internal service-to-service. HSTS preloaded.

Org-scoped

Database

PostgreSQL with at-rest encryption at the cluster level; per-tenant logical isolation enforced at the ORM layer.

PITR · 5min

Backups

Daily encrypted snapshots, 30-day retention. Point-in-time recovery to within 5 minutes on The Firm.

§ Section II · Access

Access, audited.

TOTP MFA is required for every user. Sessions are signed HttpOnly cookies — no JWT-in-localStorage. Seven roles share one database with org-scoping on every endpoint to prevent client-list fingerprinting.

Required

Multi-factor

TOTP-based, per user, with admin-resettable recovery codes. SAML / SSO on The Firm.

Hardened

Session model

Cross-subdomain cookies, signed and HttpOnly; idle timeout configurable per role. No JWT-in-localStorage.

7 · 1 DB

Role isolation

Seven roles, one database. Org-scoping on every endpoint — an attacker cannot fingerprint your client list.

ACL · presigned

Document access

Per-taxpayer ACL on every blob. Time-limited presigned URLs; never publicly listable.

§ Section III · Audit

Every move, on the record.

An append-only log of consequential actions, enforced by the database. Case assignments, stage changes, document downloads, e-signatures, return review and approval, sign-ins and access changes all carry actor + timestamp.

Append-only

Action log

Case assignments, stage changes, document downloads, e-signatures, return review and approval, sign-ins and access changes are logged with actor and timestamp.

Self-serve

In the app

Owners and office admins can search and filter their firm’s audit log, scoped to their firm alone.

Append-only

Enforced in the database

A database trigger rejects every update, delete or truncate of the log, whether it comes from the app, the admin console or raw SQL.

§ Section IV · Compliance

Compliance, shipped.

ISO 27001 certified and designed against IRS Pub 4557 and Pub 5708. Standard DPA for firms with EU clients. Data residency options on The Firm — US-east default, EU-west and APAC available.

Certified

ISO 27001

Information-security management certified to ISO/IEC 27001. Our controls are independently audited, not self-asserted.

Pub 4557 / 5708

IRS guidance

Aligns with IRS Publication 4557 (Safeguarding Taxpayer Data) and Pub 5708 (Creating a Written Information Security Plan).

EU · UK · GDPR

DPA

Standard data-processing agreement for firms with EU clients on FBAR / streamlined filings. Sub-processor list maintained publicly.

us-east-1

Data residency

US-east by default. EU-west and APAC residency on The Firm.

§ Certifications

Independently verified.

Audited, not self-asserted
ISO/IEC 27001 information-security certified
ISO 27001 certified
Enrolled Agents, enrolled to practice before the IRS
Enrolled Agents
GDPR compliant
GDPR compliant
“If we filed it, the platform recorded it — with our initials. The audit log we sell to firms is the audit log we use ourselves.”

— TaxSQR Security Note · May 2026