Security and Compliance at Promax TaxStreamLine
Promax TaxStreamLine is built to protect the sensitive tax and identity data accounting firms handle every day. This page details our security posture, certifications, and data handling practices.
Last updated: August 2026
Company Identity
Compliance & Certifications
The standards and frameworks we adhere to (or are working toward) to keep client data safe.
SOC 2
Promax TaxStreamLine is hosted on SOC 2 Type II certified AWS data centers operated by Supabase. We inherit these infrastructure controls; independent SOC 2 certification for the Promax application layer is on our roadmap.
GLBA-Aligned Security Controls
Financial-data safeguards modeled on the GLBA Safeguards Rule: AES-256 encryption, immutable audit trails, strict per-firm data isolation, role-based access, and documented incident response.
IRS Security Guidelines
We follow the security practices published for tax professionals (IRS Publication 4557 / Security Six): multi-factor authentication, access controls, encryption, monitoring, backups, and a written information security plan.
HIPAA
Promax TaxStreamLine does not process Protected Health Information (PHI). The platform handles tax and accounting documents, not healthcare records.
ISO 27001
Our hosting provider (AWS, via Supabase) is ISO 27001 certified. Promax adopts ISO 27001-aligned controls internally; formal certification is planned.
Promax TaxStreamLine is hosted on SOC 2 Type II and ISO 27001 certified AWS data centers; those attestations are inherited from our infrastructure provider. GLBA-aligned safeguards and IRS security guidelines reflect Promax's own data-handling practices.
Data Encryption
How data is protected in transit and at rest.
Encryption in Transit
All traffic between clients and Promax TaxStreamLine is encrypted with TLS 1.3. HSTS is enforced and certificates are issued by a public CA and rotated automatically.
Encryption at Rest
The database and object storage (uploaded documents) are encrypted with AES-256 at rest, provided by Supabase on AWS US East.
Key Management
Encryption keys are managed by the hosting provider (Supabase/AWS KMS). Keys are generated, stored, and rotated under AWS key management policies; application secrets are never hard-coded and are injected at runtime.
Data Residency & Jurisdiction
Where client data lives and which laws apply.
Backups & Disaster Recovery
How we protect against data loss and ensure recoverability.
Access Control & Monitoring
Who can reach client data and how we watch for abuse.
Authentication & Authorization
Email/password with optional TOTP two-factor authentication, role-based access (admin, preparer, reviewer), Row-Level Security isolating every firm by firm_id, and active-session management.
Audit Logging
Material actions (login, document access, exports, permission changes) are logged per firm and available to firm administrators.
Security Monitoring
Application errors and security-relevant events are captured via in-app observability and Sentry; anomalous activity triggers alerts to the security team.
Data Retention & Portability
Data retention follows a single policy across Promax TaxStreamLine. While the subscription is active, client data is retained for the duration of the subscription. After cancellation, account access and login profiles are deactivated 30 days after the cancellation date. Uploaded tax documents are retained by default for up to 7 years, aligned with extended IRS audit lookback periods, unless the firm requests earlier permanent deletion via a signed request from an authorized firm administrator. No liability waiver is required for deletion. Firm administrators may also export a full copy of their data at any time from the admin dashboard. Accounting firms remain responsible for maintaining their own records in line with their professional and regulatory obligations.
Subprocessors
Third parties that may process client data on our behalf.
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase (AWS) | Database, authentication, and document storage | US East (N. Virginia) |
| Stripe | Subscription billing and payments | United States |
| Lovable AI Gateway | Document OCR and AI assistant processing | United States |
| AWS (via Supabase) | Application hosting and CDN delivery | US East (N. Virginia) |
| Email service provider | Transactional and notification email | United States |
We notify customers in advance of any material changes to this list.
Incident Response & Vulnerability Reporting
Incident Response Process
Suspected incidents are triaged within 24 hours. Affected firms are notified without undue delay, and a post-mortem is published after resolution.
Vulnerability Reporting
Report vulnerabilities to security@promaxtaxstreamline.com. We acknowledge reports within 2 business days and coordinate disclosure with the reporter.