Security & enterprise
Designed for firms trusted with taxpayer data.
TaxSwarm treats security as a product requirement for firm operations: tenant isolation, encryption, professional records, on-prem deployment options, and GLBA-aware data handling.
Control room
Security reads as an operating system for firm operations.
Each control maps to a product behavior a CPA firm can evaluate during diligence.
Active control
Tenant isolation
Firm-scoped clients, analyses, documents, decisions, and exports stay inside the authenticated tenant boundary.
Security pillars
Professional controls for professional tax work.
The platform is built around the assumption that production taxpayer data may follow every path synthetic data does during testing.
Infrastructure Security
SOC 2-aligned cloud infrastructure, per-tenant isolation, monitoring, vulnerability scanning, and network segmentation.
Data Encryption
AES-256 encryption at rest, TLS 1.3 in transit, encrypted backups, and managed key rotation.
Access Controls
Role-based permissions, MFA expectations, configurable session policies, and administrative access logging.
Professional Records
Durable event history for access, decisions, strategy provenance, exports, and review activity.
No Model Training
Client data is used for the firm’s analysis workflow, not to train shared models or enrich another firm’s output.
Data Lifecycle
Retention, export, deletion, and data residency workflows designed around tax-professional obligations.
Cloud and On-Prem
Choose the operating model that matches the firm’s risk posture.
Most firms want managed cloud speed. Some enterprise firms need full private-network control. The product architecture should support both postures.
Tax practice context
Security decisions affect compliance confidence.
Controls should support tax-professional expectations including GLBA Safeguards Rule posture, IRS Publication 4557-style safeguards, IRC §7216 sensitivity, and durable engagement records.
Auditability
Every strategy needs a provenance trail.
Firm users should be able to see which facts were used, which strategies were excluded, which validation checks passed, and which CPA decisions changed the engagement record.
Ready for review
Review deployment and data handling before your first production workflow.
We’ll walk through cloud, on-prem, tenant isolation, professional records, and firm access-control expectations.