Information Security Whitepaper
UniFinTax Security Architecture & Data Safeguards
Standard: IRS Pub 4557 / NIST SP 800-53
Cipher: AES-256-GCM authenticated
Hashing: SHA-256 & HMAC-SHA256
1. IRS Publication 4557 Standards Compliance
The Internal Revenue Service, through Publication 4557 ("Safeguarding Taxpayer Data: A Guide for Your Business"), mandates that tax professionals implement comprehensive physical, administrative, and technical safeguards to protect client sensitive data. UniFinTax operates an information security program meeting and exceeding every Pub 4557 mandate, including:
- Written Information Security Plan (WISP): A formalized, continuously audited security plan governed by designated compliance officers.
- Access Controls & Least Privilege: Access to taxpayer returns and source documents is strictly limited to CPAs and preparers actively assigned to that taxpayer's case.
- Annual Third-Party Penetration Testing: Regular security audits testing for OWASP Top 10 vulnerabilities, unauthorized privilege escalation, and injection vectors.
2. Bank-Grade AES-256-GCM Vault Encryption
Every file uploaded to the UniFinTax platform—including Forms W-2, 1099, passport scans, foreign bank statements, and finalized Form 1040 tax returns—is encrypted at rest using Advanced Encryption Standard (AES) in Galois/Counter Mode (GCM) with 256-bit keys.
- Authenticated Encryption: AES-256-GCM produces a 128-bit authentication tag for every file. If even a single bit of encrypted data is modified or corrupted, decryption fails instantly, preventing bit-flipping attacks.
- Unique Initialization Vectors (IVs): Every file encryption operation uses a cryptographically secure, randomized 12-byte initialization vector, ensuring identical files produce completely dissimilar ciphertexts.
- Envelope Key Management: Master cryptographic keys are stored securely outside the database and web environment, separated from encrypted assets.
3. TLS 1.3 In-Transit Encryption & HSTS Preload
All network transmissions between your browser, our mobile applications, and our server infrastructure are encrypted using modern Transport Layer Security (TLS 1.3) with fallbacks strictly limited to TLS 1.2. Legacy protocols (SSLv3, TLS 1.0, and TLS 1.1) and insecure ciphers are disabled at the web server and load balancer layers.
We enforce HTTP Strict Transport Security (HSTS) with a max-age=31536000 header and preloading, guaranteeing that user browsers never connect over insecure plain HTTP.
4. Isolated Private Storage Architecture (Outside Web Root)
Unlike conventional web applications that store uploads in public web directories, UniFinTax employs a strict split-root physical isolation architecture:
- Storage Outside Public Root: The physical storage directory holding encrypted documents is located entirely outside the public HTML folder (
unifintax_core/storage/app/vault/). It cannot be browsed, accessed, or indexed via direct URL.
- Zero Direct Links: Files can never be downloaded directly. Requests pass through an authenticated controller pipeline that validates role authorization, decrypts the binary payload in-memory, and streams the decrypted bytes with anti-caching security headers.
- Magic-Byte MIME Validation: File uploads are inspected by inspecting byte signatures (magic bytes) to verify genuine PDF, JPG, or PNG files, eliminating executable upload exploits.
5. Dual-Table Staff vs Client Physical Database Segregation
To eliminate lateral privilege escalation vulnerabilities, UniFinTax enforces physical architectural segregation between firm personnel and external taxpayer clients:
- Distinct Physical Tables: Firm staff (CPAs, managers, support specialists, administrators) are stored exclusively in the
staff table. Taxpayers exist only in the users table.
- Dual Laravel Auth Guards: Staff authenticate through the isolated
staff guard via /staff/login. Taxpayers authenticate through the web guard via /login.
- Boundary Immunity: Even in the event of an authentication vulnerability on the taxpayer gateway, an attacker cannot pivot into firm staff administrative cockpits.
6. Native RFC 6238 TOTP Multi-Factor Authentication
UniFinTax incorporates native Time-Based One-Time Password (TOTP) multi-factor authentication compliant with IETF RFC 6238. Two-factor authentication is mandatory for all CPA preparers and administrative staff, and available as a self-service option for all taxpayer clients:
- Standard Authenticator Compatibility: Seamlessly compatible with Google Authenticator, Microsoft Authenticator, 1Password, and hardware YubiKeys.
- Emergency Recovery Ledger: Upon 2FA enablement, clients are issued eight 16-character single-use emergency recovery codes hashed using Bcrypt before storage.
- Strict Anti-Brute-Force Lockout: Authentication attempts are rate-limited to 5 tries per minute, with automatic IP throttling upon repeated failure.
7. Tamper-Evident HMAC-SHA256 Audit Ledger Chaining
Every document upload, decryption preview, questionnaire modification, message dispatch, invoice transaction, and status transition is recorded in our immutable audit ledger (audit_logs table):
Each record incorporates an HMAC-SHA256 cryptographic signature calculated over the timestamp, actor identity, action type, IP address, and the cryptographic hash of the previous ledger entry. This creates an unbroken, tamper-evident hash chain. If any database administrator or rogue query alters a past audit record, the cryptographic chain is broken immediately alerting the executive compliance team.
8. IRS Modernized e-File (MeF) Transmission Channels
Electronic filing transmissions to the Internal Revenue Service and state departments of revenue are conducted through authorized, authenticated IRS MeF XML Transmission Gateways:
- ETIN & EFIN Credentials: Transmissions utilize our registered Electronic Filer Identification Number (EFIN) and Electronic Transmitter Identification Number (ETIN).
- End-to-End Validation: Returns are pre-validated against IRS Business Rules schemas prior to submission, minimizing rejection codes.
- Cryptographic Acknowledgments: IRS acceptance tokens and state electronic acknowledgments are cryptographically signed and stored permanently in the taxpayer's case vault.
9. Inactivity Session Controls & Concurrent Session Tracking
To protect taxpayer information on unattended or shared workstations, UniFinTax enforces automated session controls required by IRS Publication 4557:
- Automatic 15-Minute Timeout: Inactive sessions automatically lock after 15 minutes of inactivity, requiring re-authentication to continue.
- Concurrent Session Monitoring: The system logs all active sessions with IP addresses, geographic location estimates, and browser user-agents. Multiple concurrent logins from differing geographical locations trigger automated security alerts.
10. Vulnerability Disclosure & Incident Response
UniFinTax welcomes responsible security research. If you believe you have discovered a potential security vulnerability, we request that you report it immediately to our security response team:
Security Incident Response Team:
UniFinTax Inc. • Office of the Chief Information Security Officer (CISO)
Email:
security@unifintax.com
PGP Fingerprint:
4A9F 82C1 B3E7 61D0 5F12 94AE 3820 D41F 77B9 C238
Response SLA: Initial acknowledgment within 12 business hours.