1099-NEC deadline · Feb 1, 2027 Tax year 2026 brings a $2,000 reporting threshold, new tips and overtime boxes, and the end of FIRE. What changed for 2026 Free FIRE converter Collect a W‑9
Trust & Security

Data Security & Compliance

Independently audited under SOC 2 Type I. HIPAA-aligned controls. 256-bit encryption at rest and in transit. Your data is protected at every layer.

Compliance & Assurance

TaxFormHero is independently audited against recognised federal and industry standards for data protection and security.

SOC 2 Type I Attestation

Independently examined under AICPA SOC 2 Type I for the Security trust services criteria, with an unqualified opinion issued by Prescient Assurance LLC as of October 28, 2025. A SOC 2 Type II observation period is now underway. The full report is available to customers and prospects under NDA.

HIPAA-Aligned Controls

HIPAA is a framework rather than a certification, and we follow it for ACA filings. Administrative, technical, and physical safeguards are in place to protect Protected Health Information (PHI) in line with the HIPAA Security Rule.

Our live Trust Center lists every control we monitor, along with current framework status and evidence. View the Tax Form Hero Trust Center.

Cybersecurity Measures

Multiple layers of security protect every account, transaction, and filing on our platform.

Two-Factor Authentication

Clients can activate 2FA via Google Authenticator or Authy by Twilio to add an additional layer of account security beyond passwords.

Web Application Firewall

Incoming traffic is filtered and inspected for harmful patterns, ensuring only authorized and authentic access is granted to the system.

Antivirus & Threat Detection

Real-time antivirus software monitors files, applications, and device behavior to detect irregularities and prevent possible attacks before they occur.

256-bit Encryption

Data-in-rest, data-in-motion, and data-in-use are all encrypted. Production database access is restricted to personnel with a specific need.

Identity Verification

One-time identity verification is required for each TaxFormHero account. This helps stop false refund claims, unauthorized form submissions, and illegal credit card use.

Fraud Pattern Detection

Pre-established fraud patterns (unique for every form type) are used to automatically identify questionable tax filings and prevent false refund claims.

Audited Access to Confidential Data

Access to confidential information — by a customer or by our own staff — is written to an audit log recording who viewed which record and when. Access to confidential data inside the company is limited to a handful of named employees.

Read-Only Support Access

Support staff can read a customer’s records in order to help with them, but cannot send, cancel, edit or accept anything on that customer’s behalf. Reading and acting are separate permissions, enforced on the server rather than hidden in the interface.

Evidenced E-Signatures

Every signed Form W‑9 records the signer’s consent, the timestamp, the originating IP address and the device signature, and each access to a request link is recorded against that request — so a signature can be evidenced after the fact, not merely asserted.

Expiring, Rate-Limited Links

Links sent to recipients carry a 64‑character random token, expire after 45 days by default, and are rate limited per minute, so a link cannot be guessed by brute force and does not stay live indefinitely.

Session Hygiene

Pages containing customer data are marked non-cacheable, so pressing Back after signing out does not bring a filled-in form or a list of payees back onto a shared screen.

Verification Freshness

An IRS name/TIN verification is treated as good for three years. When one lapses the payee returns to the list to be checked again, so a filing is never made on the strength of a match that is too old to mean anything.

Preventive Practices

DevSecOps

Security is integrated throughout the development cycle using DevOps methodology, ensuring secure software creation with common security measures applied at every stage.

Threat Modeling

Plans to eliminate and neutralize possible security risks and weaknesses are created during application development — before issues reach production.

API Security

A dedicated security checklist for APIs identifies and removes potential security flaws in our API endpoints, protecting sensitive data from exposure.

Incident Management

Simplified countermeasures are in place for any unforeseen security incidents, with a consistent escalation process including clearly defined individuals and notification protocols.

Data Loss Prevention

Standard DLP procedures are followed to prevent sensitive data from being lost or exfiltrated. Regular data backups are executed and data is fragmented as an additional safeguard.

Security Standards & Testing

Security Policies

Comprehensive security rules covering periodic audits, vulnerability assessments, access controls, and encryption techniques are strictly adhered to across the organization.

Security Awareness Training

The TaxFormHero team is well-versed in data security and consistently stays informed of emerging technologies and security measures. This awareness culture fortifies our collective defense.

Penetration Testing

Penetration testing procedures are aligned with OWASP guidelines — a thorough manual for locating and addressing security flaws in web applications. Systems are tested regularly to find weaknesses.

Monitoring & Response

Our application and network are routinely scanned and monitored for security risks. Event logs are analyzed whenever a threat is detected to enable preventive mitigation.

Server Hardening

A series of server hardening procedures is in place to eliminate attack surfaces on our servers, following industry best practices for system security.