Security
Last updated: August 3, 2026
Taxhance is built to handle sensitive financial data. Security is not an add-on. It is foundational to every layer of our platform, from infrastructure to AI processing.
Data Encryption
AES-256 encryption at rest and TLS 1.3 encryption in transit protect every document and message.
Infrastructure
Hosted on Microsoft Azure (SOC 2 Type 2 and ISO 27001 certified) with U.S.-based data centers and enterprise-grade DDoS protection.
Access Controls
Role-based permissions with granular team-member and client access scopes.
Audit Trails
Every sign-in, document upload, share, download, permission change, and administrative action is logged with actor, timestamp, IP, and affected entity. Audit history is retained for up to 1 year and exportable on request.
Compliance
Hosted on Microsoft Azure infrastructure, which maintains SOC 2 Type 2 and ISO 27001 certifications. Taxhance is actively pursuing its own SOC 2 Type 1 certification and is GDPR compliant.
AI Data Privacy
Zero Data Retention (ZDR) policy for AI processing. Client data is never stored by AI services or used for model training. Documents are classified and context is immediately discarded.
IRS Section 7216-Compliant Workflow
AutoKey provides U.S.-based auxiliary data-entry services solely for tax return preparation, consistent with Treasury Regulation §301.7216-2(d)(1).
Only Your Team Has Access
Only your team touches your data. No one on our end can access the data.
System Updates
Our infrastructure receives regular security patches and updates. We perform continuous vulnerability scanning and threat monitoring to identify and address potential risks before they become issues.
Security FAQ
Is my clients' tax data encrypted?
Does Taxhance use my data to train AI models?
Can Taxhance team members see my data?
Where is my data stored?
How long do you retain audit logs?
Questions?
If you have security questions or need to report a vulnerability, contact us at contact@taxhance.com.