Trust & Security Center

Tax data is the most sensitive data there is.

SSNs, income, dependents, bank routing — we treat it accordingly. This is how TaxWallet encrypts, isolates, and audits client data at every layer, the controls a cautious ERO can forward straight to their compliance person, and where our security program is headed next.

Encrypted in transit & at restIRS-authorized e-fileSOC 2-alignedAudit logging on every return

Security at every layer

Not a checklist for the marketing page — the controls the platform actually runs on.

Encryption everywhere

Client data is encrypted in transit and at rest. Sensitive fields never sit unprotected in the browser or on disk — encryption is the default, not an upgrade.

  • TLS on every connection
  • Encryption at rest for stored records
  • No plaintext PII in local browser storage

Access controls & MFA

Every preparer, reviewer, and ERO is scoped to exactly what they need. Multi-factor authentication and per-office isolation keep client records compartmentalized.

  • Role-based permissions per office
  • Multi-factor authentication on accounts
  • Client data isolated per office and EFIN

Audit logging

Who viewed a return, who changed a field, who transmitted it — recorded and time-stamped. When a compliance question comes up, the trail is already there.

  • Time-stamped activity history
  • Full trail across the return lifecycle
  • Exportable records for compliance reviews

IRS-authorized e-file

TaxWallet is an IRS-authorized e-file provider. Returns are validated against current IRS rules before transmission, aligned with IRS Publication 1345 safeguards.

  • IRS-authorized e-file provider
  • IRS Publication 1345 aligned
  • Pre-submission validation on every return

Resilient infrastructure

The same infrastructure runs 50+ offices and three white-label brands. Redundancy and monitoring keep filing and disbursements moving through peak season.

  • Monitored, redundant infrastructure
  • Built for filing-season load
  • Multi-bank routing for fundings

Private by design

Client data is never sold or shared with third parties. What you store and who can access it stays under your control — for the office and the taxpayer.

  • Never sold, never shared
  • Taxpayer controls who sees their return
  • Data minimization by default

A layered security model defense in depth

Client data passes through five layers of protection on its way to the IRS. Each one is a separate control — so no single failure exposes a return.

Layer 1

Transport layer

TLS on every connection. Nothing moves between a browser and the platform in the clear.

Layer 2

Access layer

Role-based permissions and multi-factor authentication decide who can reach a record before anyone does.

Layer 3

Tenant isolation

Each office and EFIN is compartmentalized. One office can never see another office’s clients.

Layer 4

Storage layer

Records are encrypted at rest; sensitive fields are protected by default, never as an upgrade.

Layer 5

Audit layer

Every view, edit, and transmission is time-stamped — so the trail exists before anyone asks for it.

Your clients' data, handled the way you’d handle it

The reassurance you can give a client who asks “is my information safe with you?” — and mean it.

It belongs to your office

TaxWallet processes client data so you can file — it is never repackaged, sold, or handed to advertisers. Your client list is your asset, not ours.

You decide who sees it

Preparers, reviewers, and front-desk staff each get exactly the access their role requires. A taxpayer sees their own return; nobody else does without permission.

It stays minimal

We collect what a return requires and no more. Data minimization is a default, which means there is less to protect and less to ever go wrong.

It leaves a record

If a client ever asks who touched their file, the answer is already written down — time-stamped, exportable, and ready for a compliance review.

SOC 2-aligned, audit on the roadmap

Our security program is built to SOC 2 Trust Services Criteria — security, availability, confidentiality. We are honest about where we are: those controls are in place and operating, and a formal SOC 2 audit is on our roadmap rather than behind us.

We will say “SOC 2-aligned” until an independent auditor lets us say more. No badges we have not earned.

On the security roadmap

  • Formal SOC 2 Type II examination
  • Expanded penetration testing cadence
  • Customer-facing audit-log exports
  • Documented incident-response playbooks

The compliance checklist, in one place

Forward this to whoever signs off on your vendors. These are the controls operating today — not aspirations.

  • Encryption in transit (TLS) and at rest
  • Multi-factor authentication on accounts
  • Role-based access scoped per office and EFIN
  • Per-tenant data isolation across all brands
  • Time-stamped, exportable audit logging
  • IRS-authorized e-file, aligned with Publication 1345
  • Pre-submission validation on every return
  • Security program built to SOC 2 Trust Services Criteria
  • No sale or third-party sharing of client data
  • Data minimization by default

Data residency & infrastructure

Client tax data is hosted on U.S.-based, monitored, redundant infrastructure — the same stack that runs 50+ offices and three white-label brands through peak filing season.

Disbursements route across multiple banking partners, so fundings keep clearing even when one bank is slow or full. Need specifics for a vendor questionnaire? Ask us directly.