BANK-LEVEL SECURITY
Data Security & Compliance
Your tax returns, SSNs, and financial data are the most sensitive information you own. We protect them with enterprise-grade infrastructure.
1. Infrastructure & Encryption
We utilize industry-leading security protocols to ensure your data is safe both in transit and at rest.
- 256-bit AES Encryption: All documents, tax returns, and financial data stored on our servers are encrypted at rest using AES-256 encryption.
- TLS 1.2+ Encryption: All data transmitted between your browser and our servers is secured using TLS 1.2 or higher.
- Secure Cloud Hosting: Our platform is hosted on top-tier cloud infrastructure (AWS) that complies with rigorous international security standards.
2. Access Controls & Authentication
We enforce strict identity verification to ensure only authorized individuals can access your data.
- Multi-Factor Authentication (MFA): Required for all Tax Strategists and internal Uncle Kam staff accessing the platform.
- Role-Based Access Control (RBAC): Internal staff only have access to the specific data required to perform their job functions (e.g., customer support cannot view your tax returns).
- Isolated Client Environments: Your data is only accessible to you and the specific Tax Strategist you have officially engaged with.
3. Regulatory Compliance
Uncle Kam is committed to meeting and exceeding federal and state regulatory requirements for financial data.
- IRS Publication 4557: We mandate that all professionals on our platform adhere to the IRS guidelines for Safeguarding Taxpayer Data.
- SOC 2 Compliance: We design our internal controls and systems in alignment with SOC 2 Type II frameworks for security, availability, and confidentiality.
- CCPA Compliance: We fully comply with the California Consumer Privacy Act regarding your data rights.
4. Incident Response & Monitoring
Security is an active process. We continuously monitor our systems for vulnerabilities.
- 24/7 Threat Monitoring: Automated systems monitor for suspicious activity, unauthorized login attempts, and potential breaches.
- Third-Party Audits: We engage independent security firms to conduct regular penetration testing and vulnerability assessments.
- Breach Notification: In the highly unlikely event of a data breach, we have a rapid response plan in place to notify affected users and regulatory bodies in accordance with state and federal laws.