Policies · Draft

Trust & Security

How the platform protects accounts and data — and what it doesn't claim.

DRAFT — legal and privacy review required before launch

This text is a working draft for review by the owner and qualified counsel. It is not a final, binding policy and has no effective date yet.

Access controls

Every database table uses row-level security: you can only read your own private records. Roles are stored separately and can't be self-assigned. Professional verification status can only be changed by an admin through an audited server function.

Private documents

Credential documents are stored in a private bucket and opened by admins only through short-lived signed links. There are no public file links.

AI safeguards

SSN/ITIN/EIN/account-number patterns are redacted before reaching AI models. Chat history is saved only with your explicit consent.

What we don't claim

TaxShifterPro does not claim any security certification or compliance audit, does not offer end-to-end encryption, has no IRS integration, and does not guarantee refunds.

Report a concern

Signed-in users can report security or scam concerns from the Support page. [REVIEW REQUIRED: security contact / disclosure policy.]