Security
Security built for government-source data.
For more than 25 years, our systems and procedures have been built around the controls required to safeguard sensitive IRS and SSA information — with recurring external review, independent testing and direct accountability to the programs whose data we handle.
Security and compliance
Built to exceed federal standards for handling tax data.
Our infrastructure is engineered to meet and exceed IRS Publication 1075, the federal standard for safeguarding Federal Tax Information, and to satisfy the Social Security Administration’s own security framework. These are not self-assessed claims — they are audited annually by the agencies themselves.
Most vendors describe their controls. Ours are examined on site by the Internal Revenue Service, the Department of the Treasury and the Social Security Administration on a published schedule, and the results are pass or fail. That is a materially higher bar than a self-declared policy.
Federal standards
Audited by the agencies whose data we handle.
Three separate federal authorities review our controls on a recurring schedule.
| Standard | What it covers | Frequency |
|---|---|---|
| IRS Publication 1075 safeguards | Controls mapped to federal requirements for protecting tax information | Continuous |
| Department of the Treasury | Annual compliance review of controls and handling | Annual audit |
| IRS electronic signature | Annual audit of electronic signature practices | Annual review |
| SSA procedural audit | Annual standards and practice review | Annual |
| SSA Section 205 | Social Security Act compliance | Continuous |
| SSA-89 audit | In-person site visit conducted by the Social Security Administration | Annual |
| PCI DSS | Payment card data security standard | Annual |
Our SSA audit history spans more than fifteen years with zero findings across fifteen consecutive annual examinations, including in-person site visits. Our recent IRS and Treasury review returned a passing score, as did our recent SSA review.
Encryption
Current standards, and the migration already planned.
Encryption is not a box to tick once. These are the standards in force today and the roadmap we are building toward, because data retained for compliance purposes has to stay protected well beyond the year it was collected.
| In force today | Migration path |
|---|---|
| TLS 1.3 with AES-256 in transit | Post-quantum cryptography |
| 256-bit AES encryption at rest | Post-quantum readiness — cryptographic inventory and migration planning toward NIST-standardized PQC algorithms, including FIPS 203/204/205 where appropriate |
| SHA-256 hashing | SHA-3 migration |
| ECDSA digital signatures | Lattice-based signatures |
Data encrypted today with today’s algorithms may still be sensitive a decade from now. Planning the migration to quantum-resistant cryptography before it is required is the difference between an orderly transition and an emergency one.
Defence in depth
Four layers, each with its own controls.
Perimeter
Web application firewall filtering and monitoring HTTP traffic against injection and cross-site scripting. DDoS protection analysing and filtering malicious requests. Intrusion prevention and detection monitoring for malicious activity in real time. Content delivery network for both performance and edge protection.
Application
Runtime application self-protection providing real-time monitoring and threat blocking inside the application itself. API gateway managing authentication, rate limiting and routing through a single controlled entry point. Development and testing against the OWASP Top 10 framework.
Data
Transparent data encryption at 256-bit AES for data at rest. Column-level encryption for the most sensitive fields, including Social Security Numbers. Tokenization converting sensitive values into non-sensitive tokens for storage and processing. Data masking so non-production environments never hold live taxpayer data.
Our in-house security team has developed software that extends native Windows Server security tooling. It integrates directly with system components to strengthen kernel-level defences and real-time monitoring, and to identify credential attacks, lateral movement and privilege escalation attempts in addition to what the standard tooling detects.
Modern threat posture
Zero trust, behavioural analytics, continuous monitoring.
- Zero Trust architecturecontinuous authentication for every user, micro-segmentation across network zones, and authenticated privileged access as the standard rather than the exception.
- Behavioral anomaly detectionaccess and system activity are monitored for anomalous behavior in addition to known indicators of compromise.
- 24/7 security operations monitoringso a threat detected at three in the morning is handled at three in the morning.
- Independent penetration testingconducted routinely, with a passing result on our most recent test.
- Chain of custody loggingevery transaction is time-stamped and recorded in a tamper-evident audit history, producing a verifiable record for each request and each transcript.
| Measure | Current | Status |
|---|---|---|
| IRS Pub 1075 compliance | Pass | Stable |
| SSA AIMS compliance | Pass | Stable |
| Unresolved critical vulnerabilities | 0 | Excellent |
| Independent penetration testing | Pass | Current |
| Treasury compliance review | Annual | Current |
For your vendor review
We have been through this many times.
Financial institutions almost always complete a security review before onboarding a verification partner. We have completed a great many of them, and we can move quickly.
- Security questionnaires completedby people who understand the controls rather than forwarded to a generic inbox.
- Documentation of our controlsprovided on request, including our federal audit posture.
- Direct conversation with your infosec staffour team will speak to your security people directly.
- Honest answers on requirements we do not meetif your review has a specific requirement, we will tell you plainly either way.
Ready when you are
Starting a vendor review?
Send us your questionnaire, or put your security team directly in touch with ours.