Security at Brevitax

IRS records and household financial data deserve serious handling. Brevitax, Inc. builds software to protect uploaded tax information — not resell it.

Brevitax, Inc. · Burbank, California

What we protect

IRS transcripts and notices, financial intake (Form 433-style), case documents, bank evidence you connect via Plaid, billing metadata, and professional work records for households and firms on Brevitax.

Encryption

TLS 1.2+ for all traffic. Provider-managed encryption at rest on database and private document storage. Application-layer AES-256-GCM for high-risk fields including Plaid access tokens and integration secrets.

Access controls

Email and password authentication with standardized password requirements. Role-based access (Admin, Sales, Resolution) with firm-scoped tenant isolation on every case and document path. Production credentials are server-side only — never exposed to browsers.

Activity and audit logging

Append-only case activity and authentication event logs support operational review and security investigations. Webhook handlers verify signatures and protect against replay.

Plaid bank connections

Before a client can open Plaid Link in the portal, we send a one-time verification code to the email on file for that case (email OTP). Plaid tokens are encrypted before storage. Disconnecting deletes credentials and stops new syncs.

Infrastructure posture

Brevitax runs on SOC 2 Type II certified infrastructure providers (Supabase on AWS, Vercel). Brevitax, Inc. maintains a documented information security program and is preparing for independent SOC 2 assessment — we describe our controls honestly as SOC 2-aligned architecture, not a completed third-party attestation.

Subprocessors

We share data only with vendors required to operate the Service. Optional integrations are enabled by you or your firm.

Supabase

Database, authentication, and private document storage (AWS infrastructure)

SOC 2 Type II certified provider

Vercel

Application hosting, edge TLS, and infrastructure analytics

Stripe

Subscription and payment processing — we do not store full card numbers

PCI DSS compliant payment processor

Anthropic

AI-assisted analysis via API — data is not used to train models per API policy

BoldSign (Syncfusion)

Electronic signature requests and completed document delivery

Resend

Transactional email (account, billing, portal verification)

Sentry

Error monitoring — PII scrubbed before transmission; replay masking enabled

Plaid

Optional bank connection — account metadata, balances, and transactions for ability-to-pay analysis

Consumer email OTP required before Plaid Link in the client portal

Google Calendar

Optional per-user calendar sync when you connect in Settings

RingCentral or Dialpad

Optional per-user telephony when your firm enables and connects an account

Google Analytics

Aggregate site and product usage measurement — not used for advertising or remarketing

Full legal detail: Privacy Policy — subprocessors

Report a security vulnerability

If you believe you have found a security issue in Brevitax, report it privately to security@brevitax.com. Please do not open public issues for security reports.

Include steps to reproduce, affected routes or features, and potential impact. We aim to acknowledge reports within three business days and work with you on coordinated disclosure. Out of scope: third-party subprocessors, denial-of-service testing without prior approval, and social engineering.

Vendor security reviews: email security@brevitax.com with your questionnaire or assessment portal invite. Operational support: support@brevitax.com · Privacy Policy · Terms of Service