Security built for tax and financial data.
Clear visibility into how we protect your data, manage risk, and stay compliant with IRS and other regulatory requirements. Review our controls, request our security documentation, and ask us anything.
- AES-256 encryption
- SOC 2 Type II in progress
- US data residency
- No AI training on your data
Compliance
View allSOC 2 Type II
In progress
FTC Safeguards
Aligned
IRS 4557 / 1345
Aligned
NIST 800-63
Aligned
Overview
Use this Trust Center to evaluate Assure Pro's security program. Review the controls that protect firm and client data, see the frameworks we align to, understand who our subprocessors are, and request our security documentation. We aim to make security diligence fast and transparent.
- Encryption
- AES-256 at rest, TLS 1.2+ in transit
- Access
- Role-based, per-firm data isolation
- Compliance
- SOC 2 in progress, GLBA aligned
Compliance
The frameworks and regulatory guidance our security program is built around.
SOC 2 Type II
In progressIndependent examination of our security, availability, and confidentiality controls. Examination underway.
FTC Safeguards Rule
AlignedControls aligned to the GLBA Safeguards Rule that applies to firms handling taxpayer financial information.
IRS Publication 4557 / 1345
AlignedSecurity practices aligned to IRS guidance for safeguarding taxpayer data and authorized e-file providers.
NIST 800-63
AlignedAuthentication and identity controls aligned to NIST digital identity guidelines.
Controls
The technical and organizational controls that protect your data across the platform.
Data protection
- Encryption at rest with AES-256
- Encryption in transit with TLS 1.2+
- Client-authorized credentials encrypted with AES-256-GCM using firm-specific keys
- Passwords hashed with bcrypt
Access control
- Role-based access control (owner, admin, and staff roles with granular permissions)
- Authentication via signed JWTs stored in httpOnly cookies
- One-time passcode verification on sign-in
- Per-firm data isolation across all client records
Infrastructure & availability
- Hosted on Amazon Web Services (AWS) in US regions
- Network and DDoS protection at the edge
- Isolated production environment with restricted access
- Error monitoring and alerting on production systems
Data governance
- Data processing agreements with all subprocessors
- Customer data is never sold or used for advertising
- Account and integration data permanently deleted within 30 days of removal
- Self-service data access and export
Responsible AI
- AI features process your data only within the platform session
- Customer and client data is not used to train AI models
- AI-generated outputs are not retained as training data
- Adheres to the Google API Services Limited Use requirements
Monitoring & audit
- Comprehensive activity logging across client, document, and workflow events
- Production database and network access restricted and logged
- Continuous review of security procedures
Resources
Security documentation available on request. Gated documents are shared under NDA.
SOC 2 Report
Available under NDA once our Type II examination is complete.
Security & Responsible AI Overview
How we protect firm and client data, and how our AI features handle it.
Privacy Policy
How we collect, use, and protect information across the platform.
Subprocessors
Third parties we rely on to operate the platform, each bound by a data processing agreement.
Amazon Web Services
Infrastructure & cloud hosting
Hosts the application, encrypted databases, and file storage. Customer data is stored and processed within AWS environments in US regions.
Resend
Transactional email
Delivers transactional email such as sign-in codes, invitations, and notifications. Message content is limited to what the notification requires.
OpenAI
AI processing
Powers in-product AI features such as document data extraction and drafting. Data is processed in-session and, under our enterprise terms, is not used to train models.
Google (Gemini)
AI processing
Powers document AI extraction. Data is processed in-session to provide the feature and is not used to train models.
Google & Microsoft
Authentication & mailbox integration
When a user connects a mailbox or signs in with a provider account, access is used solely to display email in the communications hub, save attachments, and authenticate the user.
Frequently asked questions
Updates
What we've shipped and what's on our security roadmap.
- Update2026
SOC 2 Type II examination underway
We have engaged an independent third-party auditor and are in the observation period for our SOC 2 Type II report.
- Roadmap2026
Expanding multi-factor authentication options
Adding app-based authenticators and passkeys alongside one-time passcodes, with the option for firms to require MFA for all client-portal users.
Have a security question?
Request access to our full documentation set, or reach our security team directly. We aim to respond to diligence requests quickly.
Looking for our privacy practices? Read the Privacy Policy.