Skip to main content
Navigated to Security — SAWD
Security & Privacy

How we protect
your financial data

SAWD handles bank data, tax records, and personal financial information. Security is not an afterthought — it is a design requirement.

🔒

Encryption

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). We never store your bank credentials — bank connections are managed exclusively through Plaid, a bank-level institution used by thousands of financial applications and regulated under SOC 2 Type II.

🏦

Bank Connections

SAWD uses Plaid to connect to your financial institutions. Plaid holds a limited-purpose credential on your behalf; SAWD never sees or stores your username or password. You can disconnect any account at any time from the Accounts section.

💳

Payments

Subscription billing is handled entirely by Stripe. SAWD does not store payment card data on our servers. Stripe is PCI-DSS Level 1 certified — the highest level of certification available in the payments industry.

🔑

Authentication

SAWD uses Google OAuth for authentication. Passwords are never stored directly — your identity is managed through your Google account. Two-factor authentication is enforced at the Google level.

📋

Tax Data & Privacy

Your tax data is stored under your account and is never shared, sold, or used to train AI models. CPA access is explicit and revocable — you grant access per-return and can withdraw it at any time. We comply with IRC §7216 requirements for tax preparer consent.

☁️

Infrastructure

SAWD is hosted on Google Cloud Platform infrastructure with automated backups, redundant storage, and a 99.9% uptime SLA. We maintain a formal incident response plan and notify affected users of any data security event within 72 hours.

🛡️

Access Controls

SAWD employees cannot access your financial data. Production data access requires multi-person approval and is audit-logged. We practice least-privilege access and conduct annual access reviews.

✅

SOC 2 Readiness

SAWD is in the process of completing SOC 2 Type I certification. Our controls cover security, availability, and confidentiality. We expect to publish our audit report in early 2027. In the interim, a security questionnaire is available to qualified enterprise customers and CPA firms — contact admin@sawd.ai.

Security Contact

To report a vulnerability, request a security questionnaire, or ask about our data practices, email security@sawd.ai. We respond to security reports within 24 hours. We do not currently operate a public bug bounty program.

Last reviewed: September 2026 · Next review: March 2027