Trust & Security
Client tax data is hosted in Canada, encrypted, role-scoped, and logged. We’ll go deeper under NDA, with the documents your reviewer needs.
The Essentials
Four things that hold true for every file we touch, before any conversation about certificates or paperwork.
Client data lives in AWS Canada Central. No replication to US regions, ever.
TLS 1.3 in transit and AES-256 at rest, including every backup.
Role-based and least-privilege. People see only the files and fields their role needs.
Key actions are logged with the actor and a timestamp, so there is always a record.
Human In The Loop
TaxGrit prepares the file to review-ready and hands it to your filing software. A preparer reviews every number, signs off, and transmits to CRA. The software never files on your behalf and never steps into the reviewer’s seat.
Data Lifecycle
Every piece of client data follows the same path, from the moment it arrives to the moment it is gone.
Client uploads land encrypted, in Canada.
Slips are read and fields flagged for review.
Review-ready files pass to your tax software.
Records are kept only as long as agreed.
On request, data is deleted on a defined path.
Controls
The specifics behind the four essentials, grouped the way a reviewer reads them. Open any row for detail.
AES-256 at rest and TLS 1.3 in transit, encrypted backups, and no replication to US regions.
Role-based access across owner, manager, reviewer, and auditor roles, least-privilege by default, time-bound production access, and MFA on every account.
Hosted on AWS Canada Central with isolated environments and hardened configurations.
Audit logging of key actions, with anomaly alerts on unusual activity.
Automated backups, tested restores, and a documented incident response plan.
Available Under NDA
The evidence a reviewer asks for, ready to share. We go into full detail once an NDA is in place.
SOC 2
Type II
A Type II report goes beyond a point-in-time check: an independent auditor observes our security controls operating across a monitoring period, then attests to how they actually held up.
Region, backups, retention, and the deletion path, all confirmed in writing.
In writingA short list of multi-tenant processors, with full handling detail available under NDA.
Under NDAHow We Operate
Certificates are a snapshot. These are the habits that keep the snapshot true the rest of the year.
Access is granted to the narrowest scope that does the job, and reviewed regularly.
Every sub-processor is vetted before it touches client data.
Your client data is yours. It is never sold and never used to train AI models.
A documented plan, with clear steps and prompt notification if anything goes wrong.
Security FAQ
The questions your reviewer will raise before signing off. If yours is not here, ask us directly.
In Canada, on AWS Canada Central. Data is not replicated to US regions.
No. TaxGrit prepares files to review-ready. Your preparer reviews and transmits to CRA using the filing software you already use.
Yes. You can export your data at any time, and we delete it on a defined path when you ask.
Only roles that need it, under least-privilege access, and every access to sensitive fields is logged.
No. Client data is never used to train AI models. It works on your file and stays put.
We follow a documented incident response plan, contain the issue, and notify affected firms promptly.
Security Resources
Documents you can take back to your team. Request any of them and we will send them over.
Talk To Us
Book a scoping call and we will walk your reviewer through residency, access, and the audit trail on your own kind of client work. Prefer to read first? Request the security brief.