Policies · Draft
Trust & Security
DRAFT — legal and privacy review required before launch
This text is a working draft for review by the owner and qualified counsel. It is not a final, binding policy and has no effective date yet.
Access controls
Every database table uses row-level security: you can only read your own private records. Roles are stored separately and can't be self-assigned. Professional verification status can only be changed by an admin through an audited server function.
Private documents
Credential documents are stored in a private bucket and opened by admins only through short-lived signed links. There are no public file links.
AI safeguards
SSN/ITIN/EIN/account-number patterns are redacted before reaching AI models. Chat history is saved only with your explicit consent.
What we don't claim
TaxShifterPro does not claim any security certification or compliance audit, does not offer end-to-end encryption, has no IRS integration, and does not guarantee refunds.
Report a concern
Signed-in users can report security or scam concerns from the Support page. [REVIEW REQUIRED: security contact / disclosure policy.]