Your clients’ data,
encrypted by default.
PBKDF2-derived AES-256 encryption at rest. A master key that lives only in memory. An audit log on every request. PII that never touches plaintext storage — and a control model built to SOC 2 expectations from day one. Security here is the foundation, not a feature you toggle on.
Encryption path
at restFour guarantees at the core.
These aren’t aspirations. They’re how the data layer is actually built — the same model that has protected real returns season after season since 2022.
PBKDF2 + AES-256 at rest
Sensitive data is encrypted with AES-256 keys derived through PBKDF2. The encryption key is never stored alongside the data it protects.
In-memory master key
The master key lives in memory for the duration of a session and is never written to disk. Close the session and the key is gone — there is nothing on the device to lift.
Audit-logged every request
Every request is recorded — who, what, when, against which record. The audit log is the source of truth for compliance and incident review.
PII never in plaintext
Personally identifiable information is never persisted in plaintext IndexedDB. What sits in browser storage is ciphertext, useless without the in-memory key.
Mapped to the framework
The five SOC 2 Trust Services Criteria.
SOC 2 measures five things. Here is what each one means — and exactly how the platform meets it today, ahead of the formal audit.
Security
Encryption at rest and in transit, least-privilege roles, and an audit log on every request keep the system and its data protected against unauthorized access.
Availability
Built against a 99.8% uptime target on independently scaling API services, so the busiest hours of the season — the night before the deadline — are the ones we are sized for.
Confidentiality
Taxpayer data is confidential by construction: ciphertext-only storage, an in-memory key, and tenant isolation enforced at the data layer rather than the UI.
Processing Integrity
A deterministic calculation engine and continuous schema validation mean a return computes the same way every time and is checked before it ever reaches the IRS.
Privacy
PII is collected for filing and nothing else, never sold, never used to train third-party models, and stored only as ciphertext bound to a key we cannot read for you.
The key that protects everything is never stored.
When a session opens, the master key is derived and held in memory. Every read decrypts on the fly; every write encrypts before it lands. The moment the session ends, the key evaporates. The key is not written to disk and decrypted data is not cached, so there is little on the device for an attacker to copy.
Defense in depth
Layers, not a single wall.
Encrypted in transit
Everything moving between client, platform, and banking partners travels over TLS. No return data crosses the wire in the clear.
Scoped, tenant-isolated data
Multi-tenant by design: an office only ever sees its own returns, clients, and ledgers. Isolation is enforced at the data layer, not the UI.
Least-privilege access
Role-based access gates what a user can see and do. Preparers, reviewers, and admins each get exactly the surface their job requires — nothing more.
Resilient infrastructure
Filing, submission, banking, and billing run as independent services on a long-term-support runtime, so they scale and fail independently under deadline load.
Validation before transmission
Form-level rules and IRS schema checks run continuously, catching bad data before it leaves — which is how the platform holds a 98% acceptance rate.
Audit trail for incident review
Because every action is recorded, an incident is investigated against a recorded source of truth — not reconstructed from memory after the fact.
Compliance you can point to
Built for the rules you already answer to.
The obligations are yours — but the technical safeguards behind them are ours. Here is how the platform maps to what the IRS and the FTC require of every preparer.
The technical safeguards Pub 4557 expects of every preparer — encryption, access controls, and audit trails — are built into the platform, not left to you to bolt on.
Paid preparers are “financial institutions” under the Safeguards Rule. TaxWallet provides the encryption, access control, and monitoring the Rule requires as a baseline.
Your required Written Information Security Plan can name TaxWallet as the technical-safeguards layer — encryption at rest, key management, and logging are already implemented. Download a fillable, IRS/FTC-aligned template you can adopt today.
Download the WISP template →Records are retained to meet IRS recordkeeping needs and removed on request. Stored records are encrypted at rest, so deletion removes the data without leaving a readable copy behind.
Comfort for everyone who touches a return.
The same architecture answers the question each person actually asks — whether it’s their own data, their clients’ data, their whole operation, or their investment.
Taxpayers
Your SSN, wages, and bank details are stored encrypted and bound to a managed key, so a lost or stolen device does not expose readable client data.
Preparers
You carry strangers’ most sensitive data and the liability that comes with it. The safeguards your obligations require are built in, so a device left on a train hands over nothing.
Multi-office EROs
Tenant isolation at the data layer means one office never sees another’s returns, and least-privilege roles give preparers, reviewers, and admins exactly their surface.
Investors & partners
A security model built to SOC 2 control expectations from day one — encryption, access control, audit logging, tenant isolation — is diligence-ready and built to scale.
SOC 2-aligned today. Audited next.
We build to SOC 2 control expectations and we will not claim a certification we don’t hold yet. Here is exactly where we stand — and what’s next.
SOC 2-aligned controls
Encryption, access control, audit logging, and tenant isolation are implemented to SOC 2 control expectations and protecting real returns now.
SOC 2 Type I audit
A formal third-party assessment of control design. We will publish it the day it is complete — and not a moment before.
SOC 2 Type II audit
Operating-effectiveness over time — the report enterprise buyers and bank partners expect — is the next milestone after Type I.
Built so the data
stays yours.
Walk through the security model with us — encryption at rest, the in-memory key, tenant isolation, and the audit trail — and see exactly how your clients’ data is handled.