Government-source verification for mortgage & banking teams (866) 850-4506   ·   Customer Login

Security

Security built for government-source data.

For more than 25 years, our systems and procedures have been built around the controls required to safeguard sensitive IRS and SSA information — with recurring external review, independent testing and direct accountability to the programs whose data we handle.

Security and compliance

Built to exceed federal standards for handling tax data.

Our infrastructure is engineered to meet and exceed IRS Publication 1075, the federal standard for safeguarding Federal Tax Information, and to satisfy the Social Security Administration’s own security framework. These are not self-assessed claims — they are audited annually by the agencies themselves.

25 YEARSOf disciplined security and data protection
15+ YEARSSSA examinations with no findings
ANNUALIVES e-signature independent audit
CURRENTIndependent penetration testing and PCI validation
What makes this different from a security page

Most vendors describe their controls. Ours are examined on site by the Internal Revenue Service, the Department of the Treasury and the Social Security Administration on a published schedule, and the results are pass or fail. That is a materially higher bar than a self-declared policy.

Federal standards

Audited by the agencies whose data we handle.

Three separate federal authorities review our controls on a recurring schedule.

StandardWhat it coversFrequency
IRS Publication 1075 safeguardsControls mapped to federal requirements for protecting tax informationContinuous
Department of the TreasuryAnnual compliance review of controls and handlingAnnual audit
IRS electronic signatureAnnual audit of electronic signature practicesAnnual review
SSA procedural auditAnnual standards and practice reviewAnnual
SSA Section 205Social Security Act complianceContinuous
SSA-89 auditIn-person site visit conducted by the Social Security AdministrationAnnual
PCI DSSPayment card data security standardAnnual
A perfect record across fifteen consecutive examinations

Our SSA audit history spans more than fifteen years with zero findings across fifteen consecutive annual examinations, including in-person site visits. Our recent IRS and Treasury review returned a passing score, as did our recent SSA review.

Encryption

Current standards, and the migration already planned.

Encryption is not a box to tick once. These are the standards in force today and the roadmap we are building toward, because data retained for compliance purposes has to stay protected well beyond the year it was collected.

In force todayMigration path
TLS 1.3 with AES-256 in transitPost-quantum cryptography
256-bit AES encryption at restPost-quantum readiness — cryptographic inventory and migration planning toward NIST-standardized PQC algorithms, including FIPS 203/204/205 where appropriate
SHA-256 hashingSHA-3 migration
ECDSA digital signaturesLattice-based signatures
Why the roadmap matters now

Data encrypted today with today’s algorithms may still be sensitive a decade from now. Planning the migration to quantum-resistant cryptography before it is required is the difference between an orderly transition and an emergency one.

Defence in depth

Four layers, each with its own controls.

Perimeter

Web application firewall filtering and monitoring HTTP traffic against injection and cross-site scripting. DDoS protection analysing and filtering malicious requests. Intrusion prevention and detection monitoring for malicious activity in real time. Content delivery network for both performance and edge protection.

Application

Runtime application self-protection providing real-time monitoring and threat blocking inside the application itself. API gateway managing authentication, rate limiting and routing through a single controlled entry point. Development and testing against the OWASP Top 10 framework.

Data

Transparent data encryption at 256-bit AES for data at rest. Column-level encryption for the most sensitive fields, including Social Security Numbers. Tokenization converting sensitive values into non-sensitive tokens for storage and processing. Data masking so non-production environments never hold live taxpayer data.

Proprietary hardening

Our in-house security team has developed software that extends native Windows Server security tooling. It integrates directly with system components to strengthen kernel-level defences and real-time monitoring, and to identify credential attacks, lateral movement and privilege escalation attempts in addition to what the standard tooling detects.

Modern threat posture

Zero trust, behavioural analytics, continuous monitoring.

  1. Zero Trust architecturecontinuous authentication for every user, micro-segmentation across network zones, and authenticated privileged access as the standard rather than the exception.
  2. Behavioral anomaly detectionaccess and system activity are monitored for anomalous behavior in addition to known indicators of compromise.
  3. 24/7 security operations monitoringso a threat detected at three in the morning is handled at three in the morning.
  4. Independent penetration testingconducted routinely, with a passing result on our most recent test.
  5. Chain of custody loggingevery transaction is time-stamped and recorded in a tamper-evident audit history, producing a verifiable record for each request and each transcript.
MeasureCurrentStatus
IRS Pub 1075 compliancePassStable
SSA AIMS compliancePassStable
Unresolved critical vulnerabilities0Excellent
Independent penetration testingPassCurrent
Treasury compliance reviewAnnualCurrent

For your vendor review

We have been through this many times.

Financial institutions almost always complete a security review before onboarding a verification partner. We have completed a great many of them, and we can move quickly.

  1. Security questionnaires completedby people who understand the controls rather than forwarded to a generic inbox.
  2. Documentation of our controlsprovided on request, including our federal audit posture.
  3. Direct conversation with your infosec staffour team will speak to your security people directly.
  4. Honest answers on requirements we do not meetif your review has a specific requirement, we will tell you plainly either way.

Ready when you are

Starting a vendor review?

Send us your questionnaire, or put your security team directly in touch with ours.