assure one
Sign inSchedule free trial
TRUST CENTER

Security built for tax and financial data.

Clear visibility into how we protect your data, manage risk, and stay compliant with IRS and other regulatory requirements. Review our controls, request our documentation, and ask us anything.

Request access Ask a question
AES-256 encryptionSOC 2 Type IIUS data residencyNo AI training on your data
AssureOne product dashboard
ComplianceIn progress
SOC 2 II
IRS 4557
Overview

Use this Trust Center to evaluate our security program - the controls that protect firm and client data, the frameworks we align to, and who our subprocessors are.

Encryption
AES-256 at rest, TLS 1.2+ in transit
Access
Role-based, per-firm data isolation
Compliance
SOC 2 in progress, GLBA aligned

Compliance

The frameworks and regulatory guidance our security program is built around.

SOC 2 Type II

SOC 2 Type II

Independent examination of our security, availability, and confidentiality controls. Examination underway.

TAC Security ESOF Shield

TAC Security ESOF Shield

Independent security validation. AssureOne holds the ESOF Shield Verified and Secured badge.

FTC Safeguards Rule

FTC Safeguards Rule

Controls aligned to the GLBA Safeguards Rule for firms handling taxpayer financial information.

IRS Publication 4557 / 1345

IRS Publication 4557 / 1345

Aligned to IRS guidance for safeguarding taxpayer data and authorized e-file providers.

NIST 800-63

NIST 800-63

Authentication and identity controls aligned to NIST digital identity guidelines.

TAC Security ESOF Shield - Verified and SecuredIssued by TAC Security

TAC Security ESOF Shield

AssureOne holds the ESOF Shield Verified and Secured badge from TAC Security, an independent security assessment provider. ESOF consolidates security findings across applications and infrastructure into a single risk view.

This validation sits alongside our SOC 2 Type II examination rather than replacing it. Where a framework is listed as aligned rather than certified, we say so plainly.

Independent assessmentVerified & Secured badge

Controls

The technical and organizational controls that protect your data across the platform.

Data protection

  • Encryption at rest with AES-256
  • Encryption in transit with TLS 1.2+
  • Client credentials encrypted with AES-256-GCM using firm-specific keys
  • Passwords hashed with bcrypt

Access control

  • Role-based access control (RBAC)
  • Per-firm data isolation on every record
  • Non-admin users see only assigned clients
  • One-time passcode verification on sign-in

Monitoring & logging

  • Comprehensive activity logging across client, document, and workflow events
  • Production database and network access restricted and logged
  • Error monitoring and alerting on production systems
  • Continuous review of security procedures

Infrastructure

  • Hosted on AWS in US regions
  • Encrypted databases and file storage
  • Network isolation and least privilege
  • Regular patching and hardening

Data governance

  • Data processing agreements with all subprocessors
  • Customer data is never sold or used for advertising
  • Account and integration data permanently deleted within 30 days of removal
  • Self-service data access and export

Responsible AI

  • AI features process your data only within the platform session
  • Customer and client data is not used to train AI models
  • AI-generated outputs are not retained as training data
  • Adheres to the Google API Services Limited Use requirements

Resources

Security documentation available on request. Gated documents are shared under NDA.

Request access
SOC 2 Report
Available under NDA once our Type II examination is complete.
Under NDA
Security & Responsible AI Overview
How we protect firm and client data, and how our AI features handle it.
Public
Privacy Policy
How we collect, use, and protect information across the platform.
Public

Subprocessors

Third parties we rely on to operate the platform, each bound by a data processing agreement.

Amazon Web Services
Infrastructure & cloud hosting

Hosts the application, encrypted databases, and file storage. Customer data is stored and processed within AWS environments in US regions.

Resend
Transactional email

Delivers transactional email such as sign-in codes, invitations, and notifications. Message content is limited to what the notification requires.

OpenAI
AI processing

Powers in-product AI features such as document extraction and drafting. Data is processed in-session and, under our enterprise terms, is not used to train models.

Google (Gemini)
AI processing

Powers document AI extraction. Data is processed in-session to provide the feature and is not used to train models.

Google & Microsoft
Authentication & mailbox

When a user connects a mailbox or signs in with a provider, access is used solely to display email, save attachments, and authenticate the user.

Frequently asked questions

We are undergoing a SOC 2 Type II examination of our security, availability, and confidentiality controls. The report will be available under NDA once issued.

Our controls are aligned to the GLBA Safeguards Rule: encryption at rest and in transit, role-based access controls, per-firm data isolation, activity logging, and data processing agreements with our subprocessors.

Customer data is stored and processed on Amazon Web Services in US regions. All data is encrypted at rest and in transit.

No. AI features process your data only within the platform session to provide the requested feature. Your data is not used to train AI models.

Every record is scoped to the owning firm and access is enforced by role-based permissions. Non-admin users only see the clients assigned to them.

You can export your data at any time. When you disconnect an integration or delete your account, the associated data is permanently deleted within 30 days.

ESOF (Enterprise Security in One Framework) is TAC Security's security assessment platform. The Verified and Secured badge shown on this page was issued to AssureOne as the outcome of that independent assessment.

Updates

What we have shipped and what is on our security roadmap.

Update2026

TAC Security ESOF Shield issued

AssureOne was issued the ESOF Shield Verified and Secured badge following an independent security assessment by TAC Security.

Update2026

SOC 2 Type II examination underway

We have engaged an independent third-party auditor and are in the observation period for our SOC 2 Type II report.

Roadmap2026

Expanding multi-factor authentication

Adding app-based authenticators and passkeys alongside one-time passcodes, with the option for firms to require MFA for all client-portal users.

Have a security question?

Request access to our full documentation set, or reach our security team directly. We respond to diligence requests quickly.

Request accessContact security