What we protect
IRS transcripts and notices, financial intake (Form 433-style), case documents, bank evidence you connect via Plaid, billing metadata, and professional work records for households and firms on Brevitax.
IRS records and household financial data deserve serious handling. Brevitax, Inc. builds software to protect uploaded tax information — not resell it.
Brevitax, Inc. · Burbank, California
IRS transcripts and notices, financial intake (Form 433-style), case documents, bank evidence you connect via Plaid, billing metadata, and professional work records for households and firms on Brevitax.
TLS 1.2+ for all traffic. Provider-managed encryption at rest on database and private document storage. Application-layer AES-256-GCM for high-risk fields including Plaid access tokens and integration secrets.
Email and password authentication with standardized password requirements. Role-based access (Admin, Sales, Resolution) with firm-scoped tenant isolation on every case and document path. Production credentials are server-side only — never exposed to browsers.
Append-only case activity and authentication event logs support operational review and security investigations. Webhook handlers verify signatures and protect against replay.
Before a client can open Plaid Link in the portal, we send a one-time verification code to the email on file for that case (email OTP). Plaid tokens are encrypted before storage. Disconnecting deletes credentials and stops new syncs.
Brevitax runs on SOC 2 Type II certified infrastructure providers (Supabase on AWS, Vercel). Brevitax, Inc. maintains a documented information security program and is preparing for independent SOC 2 assessment — we describe our controls honestly as SOC 2-aligned architecture, not a completed third-party attestation.
We share data only with vendors required to operate the Service. Optional integrations are enabled by you or your firm.
Database, authentication, and private document storage (AWS infrastructure)
SOC 2 Type II certified provider
Application hosting, edge TLS, and infrastructure analytics
Subscription and payment processing — we do not store full card numbers
PCI DSS compliant payment processor
AI-assisted analysis via API — data is not used to train models per API policy
Electronic signature requests and completed document delivery
Transactional email (account, billing, portal verification)
Error monitoring — PII scrubbed before transmission; replay masking enabled
Optional bank connection — account metadata, balances, and transactions for ability-to-pay analysis
Consumer email OTP required before Plaid Link in the client portal
Optional per-user calendar sync when you connect in Settings
Optional per-user telephony when your firm enables and connects an account
Aggregate site and product usage measurement — not used for advertising or remarketing
Full legal detail: Privacy Policy — subprocessors
If you believe you have found a security issue in Brevitax, report it privately to security@brevitax.com. Please do not open public issues for security reports.
Include steps to reproduce, affected routes or features, and potential impact. We aim to acknowledge reports within three business days and work with you on coordinated disclosure. Out of scope: third-party subprocessors, denial-of-service testing without prior approval, and social engineering.
Vendor security reviews: email security@brevitax.com with your questionnaire or assessment portal invite. Operational support: support@brevitax.com · Privacy Policy · Terms of Service