How 1099FIRE protects your data
You're trusting us with SSNs, TINs and financial details. Here's exactly how we protect them, and what our independent SOC 2 Type 2 audit covers.
SOC 2 Type 2
- Report
- SOC 2 Type 2
- Auditor
- Sensiba LLPIndependent CPA firm
- Latest report
- June 1 to November 30, 2025Issued December 18, 2025
- Result
- Clean opinionNo exceptions noted
- Criteria covered
- Security, Availability, Confidentiality
- Current observation period
- December 1, 2025 to November 30, 2026Under way, report expected December 2026
What this means for you
A SOC 2 audit is done by an independent CPA firm. It checks whether a company has the right controls in place to protect customer data.
Type 2 is the tougher version. Instead of looking at our controls on a single day, the auditor tested whether they actually worked across six months. They did, with no exceptions.
And it didn't stop there. Our current observation period started December 1, 2025, the day after the last one ended, and runs through November 30, 2026. Sensiba expects to issue that report in December 2026.
So you don't have to take our word for it. An outside firm has been auditing how we protect your data since June 2025, without a break.
How your data moves
From the moment you upload a file to the moment your returns reach the IRS, your data is protected at every step.
Your files
You upload them through your secure client portal
encrypted
Secure portal
Access limited to you and authorized 1099FIRE staff
AES-256
1099FIRE systems
Encrypted storage, daily backups and multi-zone cloud hosting
encrypted
IRS
Returns transmitted to the IRS electronically, encrypted in transit
How we protect your data
Every safeguard below was tested by Sensiba as part of our SOC 2 Type 2 audit.
Encryption everywhere
AES-256 for stored data, TLS 1.2 or higher for data in transit, and full-disk encryption on staff computers.
Need-to-know access
Access is granted by role and kept to the minimum each job requires. We review it every quarter.
Multi-factor sign-in
Staff need multi-factor authentication to reach sensitive systems, and every person has their own login.
Resilient hosting
Our systems run on Render and Supabase across multiple availability zones, so one data center outage doesn't stop us.
Daily backups
Production systems are backed up every day. We test our disaster recovery plan at least once a year.
Always monitored
Drata watches our controls around the clock. Automated alerts flag suspicious traffic, and we scan for vulnerabilities.
Screened, trained team
Background checks for new hires, security training every year, and confidentiality agreements for all staff.
Reviewed changes
Every software change is reviewed and tested by a second person, in a separate environment, before it goes live.
Standards we follow
SOC 2 Trust Services Criteria
Our program is built around the Security, Availability and Confidentiality criteria, and audited against them every year.
Publication 4557
We align with the IRS guide to Safeguarding Taxpayer Data.
A2A approved
1099FIRE is approved by the IRS for A2A filing. Returns are transmitted electronically and encrypted.
Coverage in place
Cyber Liability, Technology Errors & Omissions, and Commercial General Liability.
Security documents
Handy for your vendor file.
Security Overview
Everything on this page as a single PDF, sized for a vendor file or a procurement review.
Privacy Policy
How we collect, use, store and protect the information you share with us, your privacy rights, and the sub-processors we use.
Read the privacy policy →Data Services Terms and Conditions
The agreement for our filing and processing services, covering responsibilities, data handling, confidentiality and retention.
Read the terms →Website Terms and Conditions
The terms covering your use of 1099fire.com itself, separate from the agreement for our filing services.
Read the website terms →Security FAQ
The SOC 2 audit
Yes. National Software, Inc., the company behind 1099FIRE, has completed a SOC 2 Type 2 examination by Sensiba LLP, an independent CPA firm.
Our most recent report covers June 1 to November 30, 2025 and was issued on December 18, 2025. Sensiba tested our controls across that whole period and noted no exceptions.
The audit is ongoing. Our current observation period runs from December 1, 2025 to November 30, 2026, and Sensiba expects to issue that report in December 2026.
A Type 1 report is a snapshot. It checks that the right controls are designed and in place on one specific day.
A Type 2 report is more like a recording. The auditor tests whether those controls actually worked, day after day, over several months. Most businesses and their auditors ask vendors for a Type 2. That's the one we have.
They're Trust Services Criteria set by the AICPA, the organization behind SOC 2. Our audit covered all three:
- Security: systems and data are protected against unauthorized access.
- Availability: the system is up when you need it, with backups and recovery plans if something goes wrong.
- Confidentiality: private information stays private, and it's securely disposed of when it's no longer needed.
Not exactly, which is why you'll see us say "audited" instead of "certified." No agency hands out a SOC 2 certificate. An independent CPA firm examines a company's controls and issues a formal opinion in a report. That report is what you'd ask a vendor for.
No. Each audit period starts the day after the last one ends, so there's no gap in coverage.
- June 1 to November 30, 2025: tested, report issued December 18, 2025.
- December 1, 2025 to November 30, 2026: observation period under way, report expected December 2026.
After that, a new 12-month period begins.
Auditors ask this a lot, and here's what covers the time since the last report:
- Our current SOC 2 Type 2 observation period has been running since December 1, 2025.
- Sensiba issued a letter on July 16, 2026 confirming that audit is under way.
- Between audits, Drata monitors our controls continuously and alerts us if anything falls out of line.
Your data
Yes, both while it's moving and while it's stored.
- In transit: data traveling between you and our system is encrypted with TLS 1.2 or higher.
- At rest: the databases that hold customer data are encrypted with AES-256.
- On our computers: staff workstations use full-disk encryption, which protects anything stored locally if a device is lost.
The 1099FIRE system runs on established cloud providers. Render hosts the application and Supabase hosts the databases.
Both run across multiple availability zones, so if one data center has an outage, the system can fail over to another. Physical security at those data centers is handled by the providers, and we review their own audit reports as part of our vendor oversight.
All production systems and databases are backed up every day, and those backups are monitored.
Backups only matter if you can restore from them, so we also run a business continuity and disaster recovery test at least once a year. Our written recovery plan spells out who does what to bring critical systems back, and it sets internal recovery time and recovery point targets.
There's an important split here.
- Your data files are not kept. We use the file you send to prepare and transmit your returns, and it's removed shortly after processing is finished. Our Data Services Terms say the same: we don't retain the Excel file you provide or the text file created for upload.
- Filing records are kept for 7 years. That means the record of what was filed, along with submission receipts and confirmations, which matches IRS requirements.
- System logs are kept for 12 months.
When data reaches the end of its retention period, it's erased using a defined secure disposal process. Because we don't hold your source files, keep your own copy of the data used for filing in case corrections or proof of filing are needed later.
Only to deliver the services you've contracted with us for. Access to it is logged and monitored. Our Privacy Policy explains exactly what we do and don't share.
Through your secure client portal, which we set up once payment is received.
Please don't send SSNs, TINs or card numbers by email, even to us. Email gets copied to multiple servers, can be forwarded by mistake, and can be read if an account is ever compromised. The portal avoids all of that.
We'll send you a payment authorization form. Fill it out and upload it with the secure upload link we provide. Your card details never have to go through email or be read out over the phone.
Don't worry, it happens. Give us a call at (480) 706-6474 and we'll get you set up to send it the secure way going forward. It's also a good idea to delete the message from your Sent folder.
People and access
Only the people whose job requires it. Access is granted by role, kept to the minimum needed, and approved before anyone gets it.
Every person has their own login, so activity can be traced to an individual. We review who has access to critical systems every quarter, and when someone leaves the company, their access is removed promptly.
Yes. Multi-factor authentication is required for access to our sensitive internal systems, on top of strong password requirements. A stolen password alone isn't enough to get in.
Yes. New hires go through a background check before they start. Everyone completes security awareness training at least once a year and signs off on our security policies.
Employment agreements also include a confidentiality agreement that covers client information.
Yes. Our support team is based in the U.S., and you'll speak directly with someone who knows the product. That matters for security too. You always know who you're dealing with.
Monitoring and response
Several ways, and they run all the time.
- Drata monitors our security controls continuously and alerts us when something falls out of line.
- Our infrastructure logs web traffic and automatically flags suspicious activity.
- We scan for technical vulnerabilities and fix what we find.
- Staff computers run antivirus software and are managed centrally.
We follow a written incident response plan. It spells out who does what, how an incident is logged, classified and tracked to resolution, and how we communicate along the way.
Every security incident is reviewed by our Chief Information Security Officer. Afterward we document what we learned and put changes in place to prevent a repeat.
Every code change is reviewed and tested by someone other than the person who wrote it. Testing happens in a separate environment from the live system, and only authorized staff can release changes to production.
All changes are tracked in version control, so we can roll back quickly if we ever need to.
We keep a register of the vendors we rely on, with written agreements and a risk rating for each. High-risk vendors get a security and compliance review, and we reassess vendor risk every year.
For our hosting providers, we also review their own independent audit reports.
Yes. We maintain Cyber Liability, Technology Errors & Omissions, and Commercial General Liability coverage.
Working with us
Yes. 1099FIRE is IRS A2A approved, which means our system transmits information returns to the IRS electronically, and those transmissions are encrypted.
Our program is built around the AICPA's SOC 2 Trust Services Criteria for Security, Availability and Confidentiality. It also aligns with IRS Publication 4557, Safeguarding Taxpayer Data.
We comply with applicable privacy laws as well, including CCPA, GDPR and HIPAA where they apply.
We don't complete third-party or custom security questionnaires, including HECVAT.
Our SOC 2 Type 2 examination and the safeguards described on this page are what we provide instead. An independent CPA firm has already tested these controls, which is stronger assurance than a self-reported questionnaire, and it's the same evidence your auditors would ask us for.
If something you need isn't answered here, call or email us and we'll talk it through.
Security works best when both sides do their part. On your side, we recommend you:
- Keep track of who on your team has access, and remove people when they leave.
- Use strong passwords, and turn on multi-factor authentication wherever it's offered.
- Send sensitive files only through the secure portal.
- Have your own backup plan in case any outside service is unavailable for a while.
Email support@1099fire.com with "Security" in the subject line, or call (480) 706-6474. Please don't include SSNs, TINs or card numbers in your message.
Report a security concern
Tell us right away
If you think you've found a security issue, or something about your account doesn't look right, let us know.
support@1099fire.com (480) 706-6474Please don't include SSNs, TINs or card numbers in your email.
Related resources
- Privacy PolicyWhat we collect, your rights, and our sub-processors
- Data Services Terms and ConditionsThe agreement covering our filing services
- Website Terms and ConditionsThe terms covering your use of this website
- Social Security Number maskingWhat SSN masking is and why it matters
- Compliance ResourcesGuides, filing deadlines, state requirements and more
Last reviewed: September 2026