Security
What we hold, and what we don’t
Fund records you enter: properties, QOZBs, asset values, testing results, and investors’ names, email addresses, states and deferred-gain figures.
We do not collect Social Security numbers, investor taxpayer identification numbers, bank details or card numbers. Filled IRS forms leave those boxes for the preparer, and card payments are handled entirely by Stripe.
Your account
- Two-step verification with any authenticator app, plus ten one-time recovery codes. Required for our own administrator account.
- Passwords are stored only as salted scrypt hashes. Sign-in pauses for 15 minutes after repeated failures, and a reset link works once, for one hour.
- Email alerts when your password or two-step verification changes, a list of recent sign-ins with IP addresses, and a button to sign out every other device.
- Firm workspaces let you give colleagues view-only or edit access instead of sharing a login.
Data protection
- HTTPS on every page and every connection to the database.
- Encryption at rest by our database provider (AES-256). Two-step secrets are additionally encrypted by the application.
- A fund’s data is used for partner offers, or sent to an outside professional, only with that fund’s signed IRC §7216 consent, and only when you send a request.
- Investor portal links are unguessable, can be replaced or turned off at any time, and show an investor only their own statement.
Where it runs
- Application hosting: Vercel (SOC 2 Type 2, ISO 27001).
- Database: Neon Postgres (encrypted at rest, SOC 2 and ISO 27001 audited).
- Payments: Stripe (PCI DSS Level 1 service provider). Email: Resend (SOC 2 Type II).
How we operate
Techlancer LLC follows a written information security plan based on the FTC Safeguards Rule (16 CFR Part 314) and IRS Publication 5708. It covers risk assessment, access control, change management through reviewed code and automated tests, monitoring, vendor oversight, data disposal, and an incident response plan that we review at least once a year.
If we learn that your data was accessed without authorization, we will tell you promptly so you can meet your own notice duties, and we will notify regulators where the law requires it.
Report a problem
Found a vulnerability or something that looks wrong? Email support@fundtaxes.com with "Security" in the subject. Please give us a chance to fix it before telling others, and don't access other people's data while testing.