SAWD handles bank data, tax records, and personal financial information. Security is not an afterthought — it is a design requirement.
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). We never store your bank credentials — bank connections are managed exclusively through Plaid, a bank-level institution used by thousands of financial applications and regulated under SOC 2 Type II.
SAWD uses Plaid to connect to your financial institutions. Plaid holds a limited-purpose credential on your behalf; SAWD never sees or stores your username or password. You can disconnect any account at any time from the Accounts section.
Subscription billing is handled entirely by Stripe. SAWD does not store payment card data on our servers. Stripe is PCI-DSS Level 1 certified — the highest level of certification available in the payments industry.
SAWD uses Google OAuth for authentication. Passwords are never stored directly — your identity is managed through your Google account. Two-factor authentication is enforced at the Google level.
Your tax data is stored under your account and is never shared, sold, or used to train AI models. CPA access is explicit and revocable — you grant access per-return and can withdraw it at any time. We comply with IRC §7216 requirements for tax preparer consent.
SAWD is hosted on Google Cloud Platform infrastructure with automated backups, redundant storage, and a 99.9% uptime SLA. We maintain a formal incident response plan and notify affected users of any data security event within 72 hours.
SAWD employees cannot access your financial data. Production data access requires multi-person approval and is audit-logged. We practice least-privilege access and conduct annual access reviews.
SAWD is in the process of completing SOC 2 Type I certification. Our controls cover security, availability, and confidentiality. We expect to publish our audit report in early 2027. In the interim, a security questionnaire is available to qualified enterprise customers and CPA firms — contact admin@sawd.ai.
To report a vulnerability, request a security questionnaire, or ask about our data practices, email security@sawd.ai. We respond to security reports within 24 hours. We do not currently operate a public bug bounty program.
Last reviewed: September 2026 · Next review: March 2027