Trust Center

Security evidence, not security marketing.

TaxSwarm is built around controlled taxpayer-data handling: deployment-flexible architecture, firm-scoped tenancy, evidence-logged AI use, and CPA review gates. Every claim on this page is backed by code, controls, or executed agreements — and we explicitly disclose what we have not yet completed.

Deployment posture

The strongest security claim is the one your firm controls.

TaxSwarm can run entirely inside your infrastructure. For firms with strict data-residency, fiduciary, or audit requirements, private deployment removes the third-party data path entirely.

Cloud (pilot default)

Documents and analyses run on SEA-hosted infrastructure with isolated firm-scoped tenancy. Inference uses commercial AI tier (no model-training opt-in by default) under executed processing agreements.

Standard SaaS pilot path.

Hybrid

Sensitive workloads route to private inference, lower-sensitivity workloads use cloud. A routing layer chooses path per task with full evidence logging.

Available for engagements with mixed sensitivity.

Current posture

Pilot-ready controls with enterprise discipline.

The statements below are intentionally evidence-precise. An automated scanner blocks any TaxSwarm material from making compliance, encryption, audit-log, or retention claims that would not be accurate for a pilot-stage platform.

SOC 2 posture

TaxSwarm maintains SOC 2-aligned control evidence for pilot diligence. A formal third-party SOC 2 attestation report is not yet available. The deletion certificates, audit logs, access events, and consent records produced by the system constitute the underlying evidence.

Auditability

Tamper-evident evidence logs for access, AI use, decisions, exports, and compliance events. Each row carries a SHA-256 checksum over (event_id, user_id, firm_id, action, resource_type, resource_id, details, timestamp).

Model training

Customer tax data is not used to train public AI models. AI calls run against commercial API tiers (no-training by contract) and every AI use event is logged with provider, model, purpose, and consent reference.

Controls

What the platform enforces.

These controls are part of the product and its evidence layer, not just policy language. Each is grounded in code we can show to your security counsel.

Secure document intake

Files are filename-validated, magic-byte checked, malware-scanned (ClamAV), encrypted, SHA-256 hashed, and written atomically. Receipts are issued per upload.

Firm isolation

All workspace users are firm-scoped. Internal admin surfaces require SEA super-admin status and are separated from firm workflows. Multi-tenant data isolation is enforced at the service layer.

Rate limiting

Per-IP and per-route limits via slowapi middleware. Guest-upload tokens have a hard cap on usage count and expiration.

AI evidence trail

Every AI-assisted action records provider, model, purpose, input hashes, consent reference, taxpayer-data categories, and Circular 230 disclosure context.

Privacy screen

Inputs to AI models are run through a privacy screen that identifies and tags sensitive taxpayer data categories before submission.

Review gates

Client-facing reports are gated by consent, CPA review, attestation, compliance checks, and export evidence. AI cannot finalize professional work without human attestation.

Support access workflow

SEA support inspection of customer data requires a documented purpose, scope, approval window, expiration, and event log. Every event in the access window is hashed and chained.

Deletion certificates

Deletion requests run legal-hold and retention checks, then generate destruction certificates with deleted-object counts, retained-exception reasons, and a certificate hash for customer attestation.

Certification bundles

Each engagement can export an auditor-ready evidence bundle containing the analysis payload, strategies, audit trail, agent runs, and compliance certificates — verifiable outside our platform.

Subprocessors & infrastructure

Disclosed dependencies, by deployment.

The applicable subprocessor list depends on the selected deployment model. Private and hybrid deployments use customer-controlled infrastructure for sensitive workloads.

Provider / ComponentPurposeStatus
Anthropic (Claude)Tax analysis and document understanding (cloud deployments only)Commercial API tier — no training; consent-gated, logged per use
Self-hosted Llama 3.x / DeepSeekInference in private and hybrid deploymentsCustomer-controlled — no third-party data path
PostgreSQL + Cloudflare TunnelData storage and TLS-terminated network ingress (cloud deployments only)Standard SaaS infrastructure under processing agreement

Roadmap and known gaps

What we have not yet completed.

We disclose gaps before counsel asks. If any of the following matters to your firm's diligence, it should be in your engagement letter as a condition or a milestone.

No formal SOC 2 report yet

We're in evidence-collection phase. The control framework is operational; the third-party attestation is a future milestone.

MFA / SSO is on the roadmap

Current authentication is password + session token. SAML SSO and MFA enrollment are planned for the next pilot cycle.

Key rotation is single-key today

Document encryption uses a single environment-supplied 256-bit key. Envelope encryption with per-engagement keys is on the roadmap.

Contact

Security questions.

Contact [email protected] for diligence materials, security questions, or vulnerability reports. Engagement-specific evidence requests are handled through the assigned engagement lead.

Ready for review

Review security before first production taxpayer data.

We'll walk through deployment options, data handling, support access, AI evidence, deletion certificates, and the open roadmap items.