Security & enterprise

Designed for firms trusted with taxpayer data.

TaxSwarm treats security as a product requirement for firm operations: tenant isolation, encryption, professional records, on-prem deployment options, and GLBA-aware data handling.

SOC 2-aligned readinessAES-256TLS 1.3Tenant isolationOn-Prem optionGLBA-aware

Control room

Security reads as an operating system for firm operations.

Each control maps to a product behavior a CPA firm can evaluate during diligence.

Active control

Tenant isolation

Firm-scoped clients, analyses, documents, decisions, and exports stay inside the authenticated tenant boundary.

Workspace routes scopedverified
Analysis artifacts scopedverified
Decision history scopedverified

Security pillars

Professional controls for professional tax work.

The platform is built around the assumption that production taxpayer data may follow every path synthetic data does during testing.

Data Encryption

AES-256 encryption at rest, TLS 1.3 in transit, encrypted backups, and managed key rotation.

Access Controls

Role-based permissions, MFA expectations, configurable session policies, and administrative access logging.

Professional Records

Durable event history for access, decisions, strategy provenance, exports, and review activity.

No Model Training

Client data is used for the firm’s analysis workflow, not to train shared models or enrich another firm’s output.

Data Lifecycle

Retention, export, deletion, and data residency workflows designed around tax-professional obligations.

Cloud and On-Prem

Choose the operating model that matches the firm’s risk posture.

Most firms want managed cloud speed. Some enterprise firms need full private-network control. The product architecture should support both postures.

AreaCloudOn-Premise
Data locationUS-based cloud infrastructureInside your controlled network
OperationsTaxSwarm managedJoint deployment with your IT team
UpdatesAutomatic platform updatesCoordinated release windows
AccessFirm tenant and workspace controlsLocal network and identity controls
Best fitFast rollout and low operational burdenStrict residency, sovereignty, or private-network requirements

Auditability

Every strategy needs a provenance trail.

Firm users should be able to see which facts were used, which strategies were excluded, which validation checks passed, and which CPA decisions changed the engagement record.

Ready for review

Review deployment and data handling before your first production workflow.

We’ll walk through cloud, on-prem, tenant isolation, professional records, and firm access-control expectations.