Security

Built like the bank vault your data deserves.

TaxBuddy is engineered around the IRS Publication 4557 safeguards and the FTC Safeguards Rule. Here is what that means in plain English.

AES-256 encryption at rest

Every uploaded document and database row is encrypted on disk. SSNs are encrypted at the field level and masked in the UI.

TLS 1.2+ in transit

All traffic between your browser, our servers, and our storage layer uses modern TLS only.

Multi-factor authentication

MFA via TOTP authenticator apps or email codes is required for client and preparer accounts.

Role-based access control

Clients, preparers, reviewers, and admins each see only what they need — enforced server-side.

Full audit trail

Every login, document access, message, and status change is logged with timestamp and IP for forensic review.

Secure document upload

Direct-to-storage uploads, signed URLs with expiry, and per-document access scoping.

Encrypted backups

Daily encrypted backups with documented retention and restore drills.

Incident response

Documented incident-response playbook covering detection, containment, notification, and post-mortem.

Written Information Security Plan

As required by IRS Publication 4557 and the FTC Safeguards Rule, Connecting Minds maintains a Written Information Security Plan (WISP) covering administrative, technical, and physical safeguards. Available to enterprise clients and auditors on request.