At rest
AWS S3 with SSE-KMS under a dedicated AWS KMS key, enforced on every upload by bucket policy. Social Security numbers and other sensitive fields are also encrypted at the application layer.
Our preparers and our preparers’ clients are on one ledger. The audit log we sell to firms is the audit log we use ourselves — encrypted at every layer, access controlled, and ISO 27001 certified.
Documents are stored on AWS S3 with SSE-KMS under a dedicated AWS KMS key, and Social Security numbers and other sensitive fields are encrypted again in the application. TLS 1.3 in transit. Database encrypted at rest at the cluster level. Daily encrypted snapshots.
AWS S3 with SSE-KMS under a dedicated AWS KMS key, enforced on every upload by bucket policy. Social Security numbers and other sensitive fields are also encrypted at the application layer.
TLS 1.3 everywhere, including internal service-to-service. HSTS preloaded.
PostgreSQL with at-rest encryption at the cluster level; per-tenant logical isolation enforced at the ORM layer.
Daily encrypted snapshots, 30-day retention. Point-in-time recovery to within 5 minutes on The Firm.
TOTP MFA is required for every user. Sessions are signed HttpOnly cookies — no JWT-in-localStorage. Seven roles share one database with org-scoping on every endpoint to prevent client-list fingerprinting.
TOTP-based, per user, with admin-resettable recovery codes. SAML / SSO on The Firm.
Cross-subdomain cookies, signed and HttpOnly; idle timeout configurable per role. No JWT-in-localStorage.
Seven roles, one database. Org-scoping on every endpoint — an attacker cannot fingerprint your client list.
Per-taxpayer ACL on every blob. Time-limited presigned URLs; never publicly listable.
An append-only log of consequential actions, enforced by the database. Case assignments, stage changes, document downloads, e-signatures, return review and approval, sign-ins and access changes all carry actor + timestamp.
Case assignments, stage changes, document downloads, e-signatures, return review and approval, sign-ins and access changes are logged with actor and timestamp.
Owners and office admins can search and filter their firm’s audit log, scoped to their firm alone.
A database trigger rejects every update, delete or truncate of the log, whether it comes from the app, the admin console or raw SQL.
ISO 27001 certified and designed against IRS Pub 4557 and Pub 5708. Standard DPA for firms with EU clients. Data residency options on The Firm — US-east default, EU-west and APAC available.
Information-security management certified to ISO/IEC 27001. Our controls are independently audited, not self-asserted.
Aligns with IRS Publication 4557 (Safeguarding Taxpayer Data) and Pub 5708 (Creating a Written Information Security Plan).
Standard data-processing agreement for firms with EU clients on FBAR / streamlined filings. Sub-processor list maintained publicly.
US-east by default. EU-west and APAC residency on The Firm.


“If we filed it, the platform recorded it — with our initials. The audit log we sell to firms is the audit log we use ourselves.”
— TaxSQR Security Note · May 2026