Security & Trust

    Security and Compliance at Promax TaxStreamLine

    Promax TaxStreamLine is built to protect the sensitive tax and identity data accounting firms handle every day. This page details our security posture, certifications, and data handling practices.

    Last updated: August 2026

    Company Identity

    Legal Entity Name
    PROMAX BUSINESS SOLUTIONS LLC
    Entity Type
    Florida Limited Liability Company (LLC)
    Registration State
    Florida, United States
    Tax ID (EIN)
    35-2639509
    Headquarters Address
    16312 Happy Eagle Dr, Clermont, FL 34714, USA
    Security Contact
    security@promaxtaxstreamline.com

    Compliance & Certifications

    The standards and frameworks we adhere to (or are working toward) to keep client data safe.

    SOC 2

    Inherited (AWS)

    Promax TaxStreamLine is hosted on SOC 2 Type II certified AWS data centers operated by Supabase. We inherit these infrastructure controls; independent SOC 2 certification for the Promax application layer is on our roadmap.

    GLBA-Aligned Security Controls

    Aligned controls

    Financial-data safeguards modeled on the GLBA Safeguards Rule: AES-256 encryption, immutable audit trails, strict per-firm data isolation, role-based access, and documented incident response.

    IRS Security Guidelines

    Safeguards in place

    We follow the security practices published for tax professionals (IRS Publication 4557 / Security Six): multi-factor authentication, access controls, encryption, monitoring, backups, and a written information security plan.

    HIPAA

    Not applicable

    Promax TaxStreamLine does not process Protected Health Information (PHI). The platform handles tax and accounting documents, not healthcare records.

    ISO 27001

    Inherited (AWS)

    Our hosting provider (AWS, via Supabase) is ISO 27001 certified. Promax adopts ISO 27001-aligned controls internally; formal certification is planned.

    Promax TaxStreamLine is hosted on SOC 2 Type II and ISO 27001 certified AWS data centers; those attestations are inherited from our infrastructure provider. GLBA-aligned safeguards and IRS security guidelines reflect Promax's own data-handling practices.

    Data Encryption

    How data is protected in transit and at rest.

    Encryption in Transit

    All traffic between clients and Promax TaxStreamLine is encrypted with TLS 1.3. HSTS is enforced and certificates are issued by a public CA and rotated automatically.

    Encryption at Rest

    The database and object storage (uploaded documents) are encrypted with AES-256 at rest, provided by Supabase on AWS US East.

    Key Management

    Encryption keys are managed by the hosting provider (Supabase/AWS KMS). Keys are generated, stored, and rotated under AWS key management policies; application secrets are never hard-coded and are injected at runtime.

    Data Residency & Jurisdiction

    Where client data lives and which laws apply.

    Data Location
    United States — AWS US East (N. Virginia)
    Infrastructure Provider
    Supabase, hosted on AWS US East (N. Virginia)
    Applicable Jurisdiction
    United States (Florida, USA)
    Cross-Border Transfers
    Data is stored in the US. Access from other regions is encrypted via TLS 1.3; no data is replicated outside the US region.

    Backups & Disaster Recovery

    How we protect against data loss and ensure recoverability.

    Backup Frequency
    Daily automated backups with point-in-time recovery (PITR) provided by Supabase
    Retention Period
    Rolling daily backups; client tax documents archived aligned with extended IRS audit lookback periods (up to 7 years)
    RTO / RPO Targets
    Target RTO 4 hours / RPO 1 hour
    Disaster Recovery Plan
    Provider-managed redundancy within AWS US East; application redeployable from version control
    Restore Testing Cadence
    Quarterly restore verification
    Last Successful Restore Test
    August 2026

    Access Control & Monitoring

    Who can reach client data and how we watch for abuse.

    Authentication & Authorization

    Email/password with optional TOTP two-factor authentication, role-based access (admin, preparer, reviewer), Row-Level Security isolating every firm by firm_id, and active-session management.

    Audit Logging

    Material actions (login, document access, exports, permission changes) are logged per firm and available to firm administrators.

    Security Monitoring

    Application errors and security-relevant events are captured via in-app observability and Sentry; anomalous activity triggers alerts to the security team.

    Data Retention & Portability

    Data retention follows a single policy across Promax TaxStreamLine. While the subscription is active, client data is retained for the duration of the subscription. After cancellation, account access and login profiles are deactivated 30 days after the cancellation date. Uploaded tax documents are retained by default for up to 7 years, aligned with extended IRS audit lookback periods, unless the firm requests earlier permanent deletion via a signed request from an authorized firm administrator. No liability waiver is required for deletion. Firm administrators may also export a full copy of their data at any time from the admin dashboard. Accounting firms remain responsible for maintaining their own records in line with their professional and regulatory obligations.

    Subprocessors

    Third parties that may process client data on our behalf.

    SubprocessorPurposeLocation
    Supabase (AWS)Database, authentication, and document storageUS East (N. Virginia)
    StripeSubscription billing and paymentsUnited States
    Lovable AI GatewayDocument OCR and AI assistant processingUnited States
    AWS (via Supabase)Application hosting and CDN deliveryUS East (N. Virginia)
    Email service providerTransactional and notification emailUnited States

    We notify customers in advance of any material changes to this list.

    Incident Response & Vulnerability Reporting

    Incident Response Process

    Suspected incidents are triaged within 24 hours. Affected firms are notified without undue delay, and a post-mortem is published after resolution.

    Vulnerability Reporting

    Report vulnerabilities to security@promaxtaxstreamline.com. We acknowledge reports within 2 business days and coordinate disclosure with the reporter.

    Security contact

    security@promaxtaxstreamline.com