Trust & Security

Security built for Canadian tax data.

Client tax data is hosted in Canada, encrypted, role-scoped, and logged. We’ll go deeper under NDA, with the documents your reviewer needs.

The Essentials

Four things that stay true for every file.

Four things that hold true for every file we touch, before any conversation about certificates or paperwork.

Residency

Client data lives in AWS Canada Central. No replication to US regions, ever.

Encryption

TLS 1.3 in transit and AES-256 at rest, including every backup.

Access

Role-based and least-privilege. People see only the files and fields their role needs.

Audit

Key actions are logged with the actor and a timestamp, so there is always a record.

Human In The Loop

Nothing is filed or finalised by AI.

TaxGrit prepares the file to review-ready and hands it to your filing software. A preparer reviews every number, signs off, and transmits to CRA. The software never files on your behalf and never steps into the reviewer’s seat.

Data Lifecycle

Where your client data goes, start to finish.

Every piece of client data follows the same path, from the moment it arrives to the moment it is gone.

  1. 1

    Ingest

    Client uploads land encrypted, in Canada.

  2. 2

    Process

    Slips are read and fields flagged for review.

  3. 3

    Hand-off

    Review-ready files pass to your tax software.

  4. 4

    Retention

    Records are kept only as long as agreed.

  5. 5

    Deletion

    On request, data is deleted on a defined path.

Controls

The controls behind the promise.

The specifics behind the four essentials, grouped the way a reviewer reads them. Open any row for detail.

AES-256 at rest and TLS 1.3 in transit, encrypted backups, and no replication to US regions.

Role-based access across owner, manager, reviewer, and auditor roles, least-privilege by default, time-bound production access, and MFA on every account.

Hosted on AWS Canada Central with isolated environments and hardened configurations.

Audit logging of key actions, with anomaly alerts on unusual activity.

Automated backups, tested restores, and a documented incident response plan.

Available Under NDA

Proof, on request.

The evidence a reviewer asks for, ready to share. We go into full detail once an NDA is in place.

Under NDA

SOC 2

Type II

A Type II report goes beyond a point-in-time check: an independent auditor observes our security controls operating across a monitoring period, then attests to how they actually held up.

  • Independently audited by a third party
  • Controls tested over time, not a one-day snapshot
  • Full report shared with your team under NDA

Data-residency detail

Region, backups, retention, and the deletion path, all confirmed in writing.

In writing

Sub-processors

A short list of multi-tenant processors, with full handling detail available under NDA.

Under NDA

How We Operate

Security is a daily habit, not a certificate.

Certificates are a snapshot. These are the habits that keep the snapshot true the rest of the year.

Least-privilege access

Access is granted to the narrowest scope that does the job, and reviewed regularly.

Vendor diligence

Every sub-processor is vetted before it touches client data.

Data ownership

Your client data is yours. It is never sold and never used to train AI models.

Incident response

A documented plan, with clear steps and prompt notification if anything goes wrong.

Security FAQ

Questions your reviewer will ask.

The questions your reviewer will raise before signing off. If yours is not here, ask us directly.

In Canada, on AWS Canada Central. Data is not replicated to US regions.

No. TaxGrit prepares files to review-ready. Your preparer reviews and transmits to CRA using the filing software you already use.

Yes. You can export your data at any time, and we delete it on a defined path when you ask.

Only roles that need it, under least-privilege access, and every access to sensitive fields is logged.

No. Client data is never used to train AI models. It works on your file and stays put.

We follow a documented incident response plan, contain the issue, and notify affected firms promptly.

Security Resources

Take the details to your team.

Documents you can take back to your team. Request any of them and we will send them over.

DPA template

Our standard data processing agreement, ready for your review.

Request

Security brief

A concise overview of controls and architecture, shared under NDA.

Request

Data deletion policy

How and when data is deleted, written down.

Request

Talk To Us

Questions about security?

Book a scoping call and we will walk your reviewer through residency, access, and the audit trail on your own kind of client work. Prefer to read first? Request the security brief.