Skip to main content
TRUST CENTER

How SAWD Protects Your Data

You're trusting us with your tax data, bank connections, and Social Security Number. We take that seriously. Here's exactly what we do to protect it.

Our commitments

Encryption everywhere

Every byte in transit uses TLS 1.2+. Every byte at rest uses AES-256. Sensitive identifiers like SSNs are encrypted with separate keys and accessed only when necessary for tax preparation.

Access logged and time-limited

When your CPA opens your return, that access is logged with a cryptographic chain that can't be tampered with. CPA access expires when your engagement ends.

Multi-factor authentication required

Every SAWD employee uses MFA. Every CPA partner does too. Account takeover is the most common attack vector for tax fraud — we make it harder.

Strict data minimization

We collect only what we need. We delete what we no longer need. Where the IRS requires retention, we keep records and tell you exactly how long.

Our compliance posture

Where we stand against key regulatory standards.

StandardStatus
GLBA Safeguards RuleCompliant
CCPA / CPRACompliant
VCDPACompliant
IRS Pub 1345 (e-file standards)In progress
IRS Circular 230Compliant via partners
Plaid Security QuestionnaireCompliant
SOC 2 Type IIn progress
SOC 2 Type IIPlanned
Annual penetration testIn progress
Consumer MFA (Plaid requirement)In progress

How we handle specific data flows

Specific answers to "what happens when..."

When you connect a bank account through Plaid

Plaid manages the bank connection. SAWD pulls transaction and balance data from Plaid. The token that authorizes access stays with Plaid — SAWD never has direct access to your bank login.

When AI categorizes a transaction

We send the AI provider only the merchant name and amount. We don't send your name, SSN, or any aggregate financial profile. Our AI providers cannot use your data to train models served to other customers.

When your CPA reviews your return

Your CPA can see only your data during the active engagement. Every view is logged. When the engagement ends, access is revoked. The CPA-client relationship is yours — SAWD facilitates but is not party to it.

When you delete your account

You can export your data first. We delete within 30 days, except where IRS retention rules require us to keep tax records (typically 7 years). Audit logs of historical access are retained for security purposes.

Your rights

Real, enforceable rights over your data.

Access: Download a copy of everything we have about you — through your account or by emailing privacy@sawd.ai.
Correction: Fix anything that's wrong. Most corrections work directly in your account.
Deletion: Close your account and we'll delete what we can within 30 days.
Portability: Get your data in a machine-readable format you can move elsewhere.
Opt-out: Stop marketing communications, optional features, or specific data uses at any time.
Audit log access: Get a copy of every access to your account. Email privacy@sawd.ai — delivered within 14 days.

Security disclosure program

If you find a vulnerability, tell us. We commit to:

Acknowledge your report within 24 hours
Investigate and respond substantively within 7 days
Not pursue legal action against good-faith researchers
Credit you publicly with permission
Report vulnerabilities to security@sawd.ai. We are working toward a formal bug bounty program and offer recognition (and case-by-case financial rewards) for material findings.

Our incident response commitment

If we have a breach affecting your data, we will:

  • Notify you without unreasonable delay — in any case within 30 days of confirmation
  • Tell you what happened, what data was involved, and what you can do
  • Notify regulators as required by law
  • Publish a post-incident review

We have a documented incident response plan. We test it.

Questions?

© 2026 SAWD.AI — Tabula Finance, Inc.