SECURITY & TRUST

Security you can depend on.
Trust you can verify.

Filed protects the most sensitive data in your firm with bank-grade security, U.S-only processing, and workflows built for the way tax professionals actually work.
check icon
US-based data residency
check icon
Bank-grade encryption
check icon
SOC 2 Compliant

At a glance

Data residency
US-only
Data in transit
TLS encryption
Data at rest
Encrypted
Client consents
7216-safe workflows
Filed is built for high-volume U.S. tax practices that can’t afford downtime, data leaks, or black-box AI.
More of what matters

Your client data stays yours

Complete data isolation with enterprise-grade controls. We treat your client data with the same care you do.
Never used for training

Your client data is never used to train our AI models. Period. Your data processes through our system and that’s it. No sharing across firms, no feeding back into the algorithm.

Encrypted everywhere

AES-256 encryption at rest and TLS 1.3 in transit. Your data is encrypted from the moment it enters our system until it leaves. No exceptions, no shortcuts.

Full audit trails

Every action logged, timestamped, and attributable. Know exactly who accessed what client data and when. Export logs anytime for your own compliance needs.

Configurable retention

Set your own data retention policies aligned with your firm’s requirements. Automated deletion when retention periods expire. You’re in control.

Role-based access

Granular permissions for partners, managers, and staff. SSO integration with your existing identity provider. The right people see the right data.

Isolated environments

Each firm’s data is logically isolated. Multi-tenant architecture with firm-level data segregation ensures your client data never intermingles with another firm’s.

More of what matters

Four guardrails every tax firm can rely on.

These principles guide every product decision, from how we architect our systems to how we support you in the middle of busy season.
U.S.-only data residency

All client data is processed and stored on U.S. servers only. We don’t ship source documents or returns offshore, ever.

Bank-grade encryption

Data is encrypted in transit and at rest. Documents, workpapers, and exports are safeguarded using modern cryptographic standards.

Compliance by design

Filed is architected around IRS, 7216, and GDPR requirements, and is fully SOC 2 compliant. Our controls cover security, confidentiality, availability, and processing integrity, with regular third-party audits and continuous monitoring.

Transparent and verifiable logic

Filed shows its work. Every step (extraction, logic, and calculations) is fully traceable and backed by source documents, so nothing happens inside a black box.

"The breakthrough came when we realized Filed wasn't trying to replace our judgment... it was like having another set of eyes that never got tired and never forgot to check something."
Andrew Schneider, CPA, Founder & CEO
Track · Arden Hills, MN
More of what matters

FAQ

Built for the complexity of real tax work
Is Filed SOC 2 compliant?
Chevron down icon

Yes. Filed is fully SOC 2 compliant. Our controls cover security, availability, confidentiality, and processing integrity, and we undergo regular third-party audits to maintain our certification.

Where is our client data stored?
Chevron down icon

All client data processed by Filed is stored on servers located in the United States. We do not send source documents or returns to offshore providers or infrastructure, and we do not use offshore staff to handle your clients’ information.

Do we need new 7216 consents to use Filed?
Chevron down icon

Filed is designed to operate within IRS 7216 requirements. Because data remains in a secure, U.S.-based environment and is used solely to deliver services to your firm, tax firms do not need additional 7216 consents beyond their existing engagement terms. That said, your own counsel should make the final call. We’re happy to provide architecture and data-flow documentation to support their review.

Does Filed use our client data to train AI models?
Chevron down icon

No. Your client data is never used to train our AI models. Period.
Your data processes through our system and that’s it. We don’t use it to improve public models, we don’t feed it back into any shared algorithm, and we don’t train across firms.
Every firm’s data stays firmly within its own environment; no mixing, no cross-practice learning, no exceptions.

Who can see our data inside Filed?
Chevron down icon

Within your firm, access is controlled by the roles and permissions you configure (e.g., preparer, reviewer, admin). Internally at Filed, production access is tightly restricted to a small, audited group of engineers and support specialists, and only for legitimate operational or support needs. We log and monitor access to production systems.

Are returns fully automated, or is there human review?
Chevron down icon

Filed's AI does the heavy lifting on document handling, tax calculation, and data entry. Some returns, like ultra-complex returns and some edge-cases are reviewed by our internal tax professionals before they’re marked reviewer-ready.

How do we talk about Filed with our clients?
Chevron down icon

Most firms explain Filed as “a secure, U.S.-based system that automates data entry and document handling so our team can spend more time reviewing and advising you.” You can position Filed as an internal efficiency tool, not a replacement for professional judgment. We can share sample language for engagement letters, privacy policies, and your website.

Can you complete our security questionnaire?
Chevron down icon

Yes. For mid-market and enterprise firms, we regularly work through IT and security questionnaires, provide detailed documentation, and collaborate with your internal stakeholders as part of vendor due diligence.

What happens if there’s an incident?
Chevron down icon

We maintain monitoring, logging, and incident-response procedures designed to detect, contain, and remediate issues quickly. In the event of a security incident affecting your data, we will notify you in line with our contractual obligations and work with your team to share the necessary details and next steps.