You're trusting us with your tax data, bank connections, and Social Security Number. We take that seriously. Here's exactly what we do to protect it.
Every byte in transit uses TLS 1.2+. Every byte at rest uses AES-256. Sensitive identifiers like SSNs are encrypted with separate keys and accessed only when necessary for tax preparation.
When your CPA opens your return, that access is logged with a cryptographic chain that can't be tampered with. CPA access expires when your engagement ends.
Every SAWD employee uses MFA. Every CPA partner does too. Account takeover is the most common attack vector for tax fraud — we make it harder.
We collect only what we need. We delete what we no longer need. Where the IRS requires retention, we keep records and tell you exactly how long.
Where we stand against key regulatory standards.
| Standard | Status |
|---|---|
| GLBA Safeguards Rule | Compliant |
| CCPA / CPRA | Compliant |
| VCDPA | Compliant |
| IRS Pub 1345 (e-file standards) | In progress |
| IRS Circular 230 | Compliant via partners |
| Plaid Security Questionnaire | Compliant |
| SOC 2 Type I | In progress |
| SOC 2 Type II | Planned |
| Annual penetration test | In progress |
| Consumer MFA (Plaid requirement) | In progress |
Specific answers to "what happens when..."
Plaid manages the bank connection. SAWD pulls transaction and balance data from Plaid. The token that authorizes access stays with Plaid — SAWD never has direct access to your bank login.
We send the AI provider only the merchant name and amount. We don't send your name, SSN, or any aggregate financial profile. Our AI providers cannot use your data to train models served to other customers.
Your CPA can see only your data during the active engagement. Every view is logged. When the engagement ends, access is revoked. The CPA-client relationship is yours — SAWD facilitates but is not party to it.
You can export your data first. We delete within 30 days, except where IRS retention rules require us to keep tax records (typically 7 years). Audit logs of historical access are retained for security purposes.
Real, enforceable rights over your data.
If you find a vulnerability, tell us. We commit to:
If we have a breach affecting your data, we will:
We have a documented incident response plan. We test it.