Encryption
Connections use TLS in transit. Social Security numbers and EINs are encrypted at rest with AES-256-GCM. Only the last four digits are stored in plaintext so staff can search and display a masked tax ID.
Trust Center
Prospects should know how W-2s, identification documents, and bank statements are handled before they upload a file. This page describes what HeyRoca actually runs today — not a future certification.
Built for independent tax and accounting firms. Keep your existing tax-preparation software.
Connections use TLS in transit. Social Security numbers and EINs are encrypted at rest with AES-256-GCM. Only the last four digits are stored in plaintext so staff can search and display a masked tax ID.
Client files live in a private object store. Browsers never receive a public bucket URL. Downloads go through authenticated app routes after HeyRoca checks the signed-in firm, portal client, or e-sign token.
Staff must complete MFA before entering the firm app. Client portal users can enroll MFA, and firms can require it. Authenticator apps (TOTP) and emailed one-time codes are supported. SMS MFA is not offered. Enrollment, verification, failures, and staff-assisted resets are written to the audit log.
Staff and portal web sessions use an approximately 8-hour JWT lifetime configured in operations. Passwords must be at least 10 characters. Password reset does not skip MFA on the next sign-in if MFA is enrolled or the firm requires it.
Staff roles (owner, admin, member) gate sensitive actions. E-sign links use unguessable tokens. Firms can require a short-lived email code before a signer sees the document.
Firm subscriptions and client invoices are processed by Stripe. Client billing uses Stripe Connect so payments go to the firm’s Stripe account.
Production data is stored in a managed PostgreSQL database with provider-managed backups. Object versioning and cross-region document replication are later milestones — not current guarantees.
Infrastructure used to run the service: Stripe, Resend, Cloudflare R2, and managed Postgres. Security contact: [email protected]. Firms can request deletion of customer data at that address.
HeyRoca is not SOC 2 certified. A formal audit is on our roadmap. We will not describe the product as SOC 2 compliant until an independent report is complete. We do not claim penetration-test reports, personnel background checks, or a published RPO/RTO.
A public draft DPA is available at /dpa. Counsel should review it before you rely on it in a customer contract. You can also reach us at [email protected].
Related: Privacy Policy · Terms of Service · DPA · Integrations