Assure Pro Trust Center

Security built for tax and financial data.

Clear visibility into how we protect your data, manage risk, and stay compliant with IRS and other regulatory requirements. Review our controls, request our security documentation, and ask us anything.

  • AES-256 encryption
  • SOC 2 Type II in progress
  • US data residency
  • No AI training on your data

Compliance

View all

SOC 2 Type II

In progress

FTC Safeguards

Aligned

IRS 4557 / 1345

Aligned

NIST 800-63

Aligned

Overview

Use this Trust Center to evaluate Assure Pro's security program. Review the controls that protect firm and client data, see the frameworks we align to, understand who our subprocessors are, and request our security documentation. We aim to make security diligence fast and transparent.

Encryption
AES-256 at rest, TLS 1.2+ in transit
Access
Role-based, per-firm data isolation
Compliance
SOC 2 in progress, GLBA aligned

Compliance

The frameworks and regulatory guidance our security program is built around.

SOC 2 Type II

In progress

Independent examination of our security, availability, and confidentiality controls. Examination underway.

FTC Safeguards Rule

Aligned

Controls aligned to the GLBA Safeguards Rule that applies to firms handling taxpayer financial information.

IRS Publication 4557 / 1345

Aligned

Security practices aligned to IRS guidance for safeguarding taxpayer data and authorized e-file providers.

NIST 800-63

Aligned

Authentication and identity controls aligned to NIST digital identity guidelines.

Controls

The technical and organizational controls that protect your data across the platform.

Data protection

  • Encryption at rest with AES-256
  • Encryption in transit with TLS 1.2+
  • Client-authorized credentials encrypted with AES-256-GCM using firm-specific keys
  • Passwords hashed with bcrypt

Access control

  • Role-based access control (owner, admin, and staff roles with granular permissions)
  • Authentication via signed JWTs stored in httpOnly cookies
  • One-time passcode verification on sign-in
  • Per-firm data isolation across all client records

Infrastructure & availability

  • Hosted on Amazon Web Services (AWS) in US regions
  • Network and DDoS protection at the edge
  • Isolated production environment with restricted access
  • Error monitoring and alerting on production systems

Data governance

  • Data processing agreements with all subprocessors
  • Customer data is never sold or used for advertising
  • Account and integration data permanently deleted within 30 days of removal
  • Self-service data access and export

Responsible AI

  • AI features process your data only within the platform session
  • Customer and client data is not used to train AI models
  • AI-generated outputs are not retained as training data
  • Adheres to the Google API Services Limited Use requirements

Monitoring & audit

  • Comprehensive activity logging across client, document, and workflow events
  • Production database and network access restricted and logged
  • Continuous review of security procedures

Resources

Security documentation available on request. Gated documents are shared under NDA.

Request access

SOC 2 Report

Available under NDA once our Type II examination is complete.

Under NDA

Security & Responsible AI Overview

How we protect firm and client data, and how our AI features handle it.

Public

Privacy Policy

How we collect, use, and protect information across the platform.

Public

Subprocessors

Third parties we rely on to operate the platform, each bound by a data processing agreement.

Amazon Web Services

Infrastructure & cloud hosting

Hosts the application, encrypted databases, and file storage. Customer data is stored and processed within AWS environments in US regions.

Resend

Transactional email

Delivers transactional email such as sign-in codes, invitations, and notifications. Message content is limited to what the notification requires.

OpenAI

AI processing

Powers in-product AI features such as document data extraction and drafting. Data is processed in-session and, under our enterprise terms, is not used to train models.

Google (Gemini)

AI processing

Powers document AI extraction. Data is processed in-session to provide the feature and is not used to train models.

Google & Microsoft

Authentication & mailbox integration

When a user connects a mailbox or signs in with a provider account, access is used solely to display email in the communications hub, save attachments, and authenticate the user.

Frequently asked questions

Updates

What we've shipped and what's on our security roadmap.

  1. Update2026

    SOC 2 Type II examination underway

    We have engaged an independent third-party auditor and are in the observation period for our SOC 2 Type II report.

  2. Roadmap2026

    Expanding multi-factor authentication options

    Adding app-based authenticators and passkeys alongside one-time passcodes, with the option for firms to require MFA for all client-portal users.

Have a security question?

Request access to our full documentation set, or reach our security team directly. We aim to respond to diligence requests quickly.

Looking for our privacy practices? Read the Privacy Policy.