Every statement below names the policy document that governs it, and a firm running diligence can ask for any of them in full.
Who is on the other end: about us. The legal terms: privacy policy and terms of service.
From the moment an identifier is typed into a form to the moment it is deleted. Each statement names the document that governs it.
Every taxpayer identifier the product stores is encrypted at rest with AES-256-GCM: the identification numbers on payers, recipients, W-9s and forms. It is decrypted only when the product needs it. The same applies to multi-factor secrets, webhook signing secrets, and the bytes of every document in the vault. Keys are versioned, so one can be rotated and the older data re-encrypted rather than stranded.
The service refuses to start in production if the encryption key is missing, is the development placeholder, or is not a valid 256-bit key. A forgotten setting cannot quietly downgrade the encryption on the data above. It takes the service down instead, which is the failure you want.
No taxpayer identifier reaches a log line. Text that is retained (audit metadata, including the filename a person chose when they uploaded a document) has anything shaped like an SSN, ITIN, EIN or email address taken out of it first, because a person who names a file after their own SSN should not thereby put it in a retained store. A standing test pushes distinctive identifiers through every path and reads back every record that results, so this is checked on every change rather than remembered.
Signing in sets an httpOnly cookie. No token is readable by page JavaScript, so a script injected into any page on this site cannot carry a session away. The cookie is same-origin (the browser talks to the API on the origin that served the page, never a second one), it is refused over plain HTTP in production, and every write additionally carries a double-submit CSRF token.
Every query is scoped by the firm on the credential, never by anything in a request; a cross-firm read returns a not-found rather than a refusal, so the existence of another firm's record is not observable.
An API key is stored only as a SHA-256 hash; the full key is displayed exactly once, at creation, and cannot be recovered afterwards. Passwords are bcrypt. Time-based multi-factor authentication is available on every account, and we will give notice in the product before it becomes mandatory for all users.
Every event we deliver to your endpoint is HMAC-signed with a per-endpoint secret, so your systems can prove an event really came from us and was not replayed or forged. The secret itself is one of the values encrypted at rest above.
Every form is checked before it is filed. Filing past a warning means acknowledging that warning by name, and the acknowledgement is recorded in the audit log against that form, with the user who made it. The audit log also records sign-ins, key lifecycle, identifier changes, submissions, completed W-9s and erasure requests.
A vault with no end date is a liability rather than a feature. These are the windows, who sets them, and what an erasure keeps.
Document retention is a per-firm setting with a floor of three years (the IRS minimum) and a ceiling of twenty-five. Documents past that window are deleted by a purge a person runs: it prints what it would do and does nothing until told a second time, it never touches a document whose tax year is unknown, and it deletes the stored bytes before the record that points at them.
A firm can erase a payer or a recipient in-product: the name, the address, the contact details and the identification number are blanked, and the stored form data is tombstoned, while the form rows and the non-identifying audit trail survive, because a filed form is a record the IRS holds whatever the firm does with its copy. The erasure is itself an audited event.
Before a payee statement is delivered electronically, the recipient is given the disclosures the IRS requires and consents to a stated scope. The version of the disclosures in force is recorded with the consent, a statement outside the consented scope is refused rather than emailed, and a withdrawal is confirmed in writing and audited, including when the confirmation could not be sent, so the firm knows a paper one is owed.
Controls without a program are features. Summarized from the internal documents, each named. A firm running diligence can ask for any of them in full.
A written information security program (the plan every professional preparer and e-file provider is required to hold) covers ten areas: its scope, a named security coordinator, an inventory of data by classification, administrative safeguards (annual risk assessment, mandatory training, least-privilege access reviewed quarterly, change management, vendor due diligence), the technical safeguards implemented in the product, physical safeguards, vendor management, incident response and breach notification, annual evaluation, and the nine policies it incorporates by reference.
The program names a security coordinator, by name and contact, who owns it, approves access, runs the annual risk assessment, reviews vendors and leads incident response. On a platform this size that is not a committee, and the page telling you who it is is one click away.
The incident-response plan defines what counts as reportable, four severity levels, and seven numbered steps from detection through post-incident review, plus playbooks for a database-credential compromise, an encryption-key compromise, a customer-credential compromise, and a breach at a provider we depend on. We notify each affected firm within 72 hours of confirming a breach of data we hold for it. As an e-file provider we notify the IRS within 24 hours of confirming a breach of taxpayer data, and under the FTC Safeguards Rule we report to the FTC no later than 30 days after discovering a notification event involving unencrypted data of 500 or more consumers. Affected individuals and state authorities are notified as the applicable law requires.
The program requires every processor that touches or could touch personal data to be assessed before use and reviewed every year. There are four: Microsoft Azure, which hosts the database, key vault, object storage and the services themselves; Stripe, the billing processor, which never sees return data; Stripe Identity, which checks each firm owner's photo ID and selfie; and Resend, the email provider, whose messages carry no return data in their bodies. From January 2027 a print and mail vendor joins them, named in the privacy policy before it is first used. The filing service that talks to the IRS is ours.
On Microsoft Azure, in the Central US region: the services, a managed PostgreSQL database, a key vault for secrets and blob storage for the document vault. There are no on-premises servers holding taxpayer data and no laptop is one. Workforce devices used to reach these systems must carry full-disk encryption, a screen lock and current patches.
Security questionnaires, data-processing agreements, requests for any of the policy documents summarized above, and vulnerability reports go to one address and reach one person. The documents are internal because they carry contact details and infrastructure names, not because they are thin.
Free to try. Nothing is filed until you say so, and no card is needed.