Independently audited under SOC 2 Type I. HIPAA-aligned controls. 256-bit encryption at rest and in transit. Your data is protected at every layer.
TaxFormHero is independently audited against recognised federal and industry standards for data protection and security.
Independently examined under AICPA SOC 2 Type I for the Security trust services criteria, with an unqualified opinion issued by Prescient Assurance LLC as of October 28, 2025. A SOC 2 Type II observation period is now underway. The full report is available to customers and prospects under NDA.
HIPAA is a framework rather than a certification, and we follow it for ACA filings. Administrative, technical, and physical safeguards are in place to protect Protected Health Information (PHI) in line with the HIPAA Security Rule.
Our live Trust Center lists every control we monitor, along with current framework status and evidence. View the Tax Form Hero Trust Center.
Multiple layers of security protect every account, transaction, and filing on our platform.
Clients can activate 2FA via Google Authenticator or Authy by Twilio to add an additional layer of account security beyond passwords.
Incoming traffic is filtered and inspected for harmful patterns, ensuring only authorized and authentic access is granted to the system.
Real-time antivirus software monitors files, applications, and device behavior to detect irregularities and prevent possible attacks before they occur.
Data-in-rest, data-in-motion, and data-in-use are all encrypted. Production database access is restricted to personnel with a specific need.
One-time identity verification is required for each TaxFormHero account. This helps stop false refund claims, unauthorized form submissions, and illegal credit card use.
Pre-established fraud patterns (unique for every form type) are used to automatically identify questionable tax filings and prevent false refund claims.
Access to confidential information — by a customer or by our own staff — is written to an audit log recording who viewed which record and when. Access to confidential data inside the company is limited to a handful of named employees.
Support staff can read a customer’s records in order to help with them, but cannot send, cancel, edit or accept anything on that customer’s behalf. Reading and acting are separate permissions, enforced on the server rather than hidden in the interface.
Every signed Form W‑9 records the signer’s consent, the timestamp, the originating IP address and the device signature, and each access to a request link is recorded against that request — so a signature can be evidenced after the fact, not merely asserted.
Links sent to recipients carry a 64‑character random token, expire after 45 days by default, and are rate limited per minute, so a link cannot be guessed by brute force and does not stay live indefinitely.
Pages containing customer data are marked non-cacheable, so pressing Back after signing out does not bring a filled-in form or a list of payees back onto a shared screen.
An IRS name/TIN verification is treated as good for three years. When one lapses the payee returns to the list to be checked again, so a filing is never made on the strength of a match that is too old to mean anything.
Security is integrated throughout the development cycle using DevOps methodology, ensuring secure software creation with common security measures applied at every stage.
Plans to eliminate and neutralize possible security risks and weaknesses are created during application development — before issues reach production.
A dedicated security checklist for APIs identifies and removes potential security flaws in our API endpoints, protecting sensitive data from exposure.
Simplified countermeasures are in place for any unforeseen security incidents, with a consistent escalation process including clearly defined individuals and notification protocols.
Standard DLP procedures are followed to prevent sensitive data from being lost or exfiltrated. Regular data backups are executed and data is fragmented as an additional safeguard.
Comprehensive security rules covering periodic audits, vulnerability assessments, access controls, and encryption techniques are strictly adhered to across the organization.
The TaxFormHero team is well-versed in data security and consistently stays informed of emerging technologies and security measures. This awareness culture fortifies our collective defense.
Penetration testing procedures are aligned with OWASP guidelines — a thorough manual for locating and addressing security flaws in web applications. Systems are tested regularly to find weaknesses.
Our application and network are routinely scanned and monitored for security risks. Event logs are analyzed whenever a threat is detected to enable preventive mitigation.
A series of server hardening procedures is in place to eliminate attack surfaces on our servers, following industry best practices for system security.
Answers come straight from our guides. For anything about your own filing, we’ll point you to a person.
Can’t find the answer? Contact us
General information, not tax advice. Please don’t type Social Security or tax ID numbers here.