Security
Security Overview
How we protect your clients' tax data. Questions: support@taxalpha.us
Tax Alpha is a planning platform for professional tax and accounting firms. We designed it around one assumption: everything a firm uploads is among the most sensitive data a person has. This page summarizes the safeguards; contractual commitments backing them are in our Data Processing Agreement.
The short version
- Your data is encrypted in transit and at rest, with an extra layer of field-level encryption on tax data.
- Identifiers (SSNs, account numbers, contact details) are stripped before any text reaches an AI model.
- AI runs on AWS Bedrock in the United States. Your data is never used to train AI models, by us or by anyone else.
- Original tax return PDFs are deleted right after data extraction.
- Each firm's data is isolated; no path in the application crosses firms.
- You can delete any record at any time, and we delete everything within 60 days if you leave.
Where data lives and who touches it
All processing and storage is in the United States. Three infrastructure providers, each under confidentiality and security obligations: Amazon Web Services (AI inference via Bedrock, OCR for scanned documents via Textract), Railway (application and database hosting), and Cloudflare (sign-on and network security). No other third party receives client data, and we never sell it or use it for advertising.
How AI sees your data (and what it never sees)
Before any text is sent to an AI model, an automated redaction pass removes Social Security numbers, EINs, addresses, emails, phone numbers, bank account and routing numbers, and dates of birth. The models analyze redacted text and return analysis, never storing what they read: under AWS Bedrock's terms, inputs are not retained and are not used for model training.
Redaction is automated and best-effort; an identifier in an unusual format can occasionally get through. The architecture assumes that: even unredacted text inside the AI boundary stays in the United States, is not retained, and is never used for training.
Tax math itself (liability, projections, strategy savings) is computed by deterministic software built from IRS worksheets, not by AI, so numbers are reproducible and auditable.
Document lifecycle
Uploads are validated, stored under randomized names, and processed promptly. After extraction, the original unredacted PDF is deleted. The copy retained for in-app preview is visually redacted, with identifiers masked, including the hidden form-field layer of fillable PDFs. Extracted text is stored only in redacted form, encrypted at the field level.
Access control
Sign-on runs through Cloudflare Access backed by your identity provider; the application refuses to start if authentication is misconfigured. Every data route is scoped to your firm. Production access on our side is limited to a small number of named individuals, and data access is audit-logged.
Resilience and accountability
Encrypted automated database backups; application audit logging; rate limiting; standard security headers; an automated test suite covering authentication, firm isolation, and encryption that runs before every deployment. If a security incident ever affects your data, we will use best efforts to notify you promptly after confirming it, with the details you need for your own obligations to clients and the IRS.
Your compliance posture
Firms are financial institutions under the FTC Safeguards Rule, and our Data Processing Agreement is written to slot into your vendor-oversight obligations (16 CFR 314.4(f)) and your IRS Publication 4557 Written Information Security Plan. We do not yet hold a SOC 2 attestation (it is on our roadmap), and on request we will complete a reasonable security questionnaire annually.
