Tax data is the most sensitive data there is.
SSNs, income, dependents, bank routing — we treat it accordingly. This is how TaxWallet encrypts, isolates, and audits client data at every layer, the controls a cautious ERO can forward straight to their compliance person, and where our security program is headed next.
Security at every layer
Not a checklist for the marketing page — the controls the platform actually runs on.
Encryption everywhere
Client data is encrypted in transit and at rest. Sensitive fields never sit unprotected in the browser or on disk — encryption is the default, not an upgrade.
- TLS on every connection
- Encryption at rest for stored records
- No plaintext PII in local browser storage
Access controls & MFA
Every preparer, reviewer, and ERO is scoped to exactly what they need. Multi-factor authentication and per-office isolation keep client records compartmentalized.
- Role-based permissions per office
- Multi-factor authentication on accounts
- Client data isolated per office and EFIN
Audit logging
Who viewed a return, who changed a field, who transmitted it — recorded and time-stamped. When a compliance question comes up, the trail is already there.
- Time-stamped activity history
- Full trail across the return lifecycle
- Exportable records for compliance reviews
IRS-authorized e-file
TaxWallet is an IRS-authorized e-file provider. Returns are validated against current IRS rules before transmission, aligned with IRS Publication 1345 safeguards.
- IRS-authorized e-file provider
- IRS Publication 1345 aligned
- Pre-submission validation on every return
Resilient infrastructure
The same infrastructure runs 50+ offices and three white-label brands. Redundancy and monitoring keep filing and disbursements moving through peak season.
- Monitored, redundant infrastructure
- Built for filing-season load
- Multi-bank routing for fundings
Private by design
Client data is never sold or shared with third parties. What you store and who can access it stays under your control — for the office and the taxpayer.
- Never sold, never shared
- Taxpayer controls who sees their return
- Data minimization by default
A layered security model defense in depth
Client data passes through five layers of protection on its way to the IRS. Each one is a separate control — so no single failure exposes a return.
Transport layer
TLS on every connection. Nothing moves between a browser and the platform in the clear.
Access layer
Role-based permissions and multi-factor authentication decide who can reach a record before anyone does.
Tenant isolation
Each office and EFIN is compartmentalized. One office can never see another office’s clients.
Storage layer
Records are encrypted at rest; sensitive fields are protected by default, never as an upgrade.
Audit layer
Every view, edit, and transmission is time-stamped — so the trail exists before anyone asks for it.
Your clients' data, handled the way you’d handle it
The reassurance you can give a client who asks “is my information safe with you?” — and mean it.
It belongs to your office
TaxWallet processes client data so you can file — it is never repackaged, sold, or handed to advertisers. Your client list is your asset, not ours.
You decide who sees it
Preparers, reviewers, and front-desk staff each get exactly the access their role requires. A taxpayer sees their own return; nobody else does without permission.
It stays minimal
We collect what a return requires and no more. Data minimization is a default, which means there is less to protect and less to ever go wrong.
It leaves a record
If a client ever asks who touched their file, the answer is already written down — time-stamped, exportable, and ready for a compliance review.
SOC 2-aligned, audit on the roadmap
Our security program is built to SOC 2 Trust Services Criteria — security, availability, confidentiality. We are honest about where we are: those controls are in place and operating, and a formal SOC 2 audit is on our roadmap rather than behind us.
We will say “SOC 2-aligned” until an independent auditor lets us say more. No badges we have not earned.
On the security roadmap
- Formal SOC 2 Type II examination
- Expanded penetration testing cadence
- Customer-facing audit-log exports
- Documented incident-response playbooks
The compliance checklist, in one place
Forward this to whoever signs off on your vendors. These are the controls operating today — not aspirations.
- Encryption in transit (TLS) and at rest
- Multi-factor authentication on accounts
- Role-based access scoped per office and EFIN
- Per-tenant data isolation across all brands
- Time-stamped, exportable audit logging
- IRS-authorized e-file, aligned with Publication 1345
- Pre-submission validation on every return
- Security program built to SOC 2 Trust Services Criteria
- No sale or third-party sharing of client data
- Data minimization by default
Data residency & infrastructure
Client tax data is hosted on U.S.-based, monitored, redundant infrastructure — the same stack that runs 50+ offices and three white-label brands through peak filing season.
Disbursements route across multiple banking partners, so fundings keep clearing even when one bank is slow or full. Need specifics for a vendor questionnaire? Ask us directly.
Go deeper
The full security architecture and our legal terms, in one place.
Platform security architecture
How encryption, isolation, and access controls are built into the stack the platform runs on.
See the architectureLegal, privacy & terms
Privacy policy, terms of service, and the agreements that govern how data is handled.
Read the legal centerFound a security issue, or have a question about our controls? support@taxwallet.ai