Security

Last updated · July  20,  2025

Protecting the confidentiality and integrity of your tax and financial information is our top priority. Our multi‑layered security program combines hardened cloud infrastructure, rigorous engineering practices, and continuous monitoring to keep your data safe while you file with confidence.

Principles

  • Defense in depth: multiple, complementary safeguards across infrastructure, application, and people.
  • Least privilege: access is granted only when required, logged, and periodically reviewed.
  • Encryption everywhere: all customer data is encrypted in transit and at rest.
  • Continuous improvement: policies, controls, and training are reassessed at least annually and after every tax season.

Infrastructure & Data Protection

Control

Cloud foundations

Encryption at rest

Encryption in transit

Private storage

Backups & disaster recovery

What We Do

Built on Google Cloud Platform (GCP), which maintains ISO 27001, SOC 1/2/3, and FedRAMP certifications.

All customer data––including tax documents and PII––is encrypted with AES‑256.

Transport Layer Security (TLS 1.2+) is enforced for every network connection between your browser, our application, and internal services.

GCP buckets are configured to block public access; signed URLs expire automatically.

Point‑in‑time database backups replicated across regions; quarterly restore tests validaterecovery objectives.