Policy
Information Security Policy
The measures AuraSoft Inc. takes to protect the confidentiality, integrity and availability of the information entrusted to AuraTax, and the rules its staff and suppliers follow.
In effect since October 5, 2026
1. Purpose and scope
This policy covers AuraTax — the Taxation, Bookkeeping and Payroll apps on the web and on the desktop, the services behind them and this website — the information they hold, and everyone who works on them at AuraSoft, including contractors. Tax returns, financial records and payroll records are confidential by nature; we treat all of the information our customers enter as confidential.
2. Responsibilities
- AuraSoft's management is accountable for information security and approves this policy.
- The Privacy Officer oversees the protection of personal information, handles incidents and answers requests (support@auratax.ca).
- Everyone with access to AuraTax systems follows this policy, keeps customer information confidential, and reports any suspected incident at once.
- Our customers control who can see their records in AuraTax and keep their own sign-in credentials secret.
3. Access control
Customers. Every request to our services must carry a valid sign-in token issued by our identity provider, Auth0, and is checked by the service it reaches. Access to a business, an employer or a return is granted by its owner, with one of three roles: owner, editor or reader. A reader cannot change anything, and a person without access is told the record does not exist.
Staff. Access to production systems is granted only to those who need it for their work, with the least privilege that work requires, and is removed when they no longer need it or leave AuraSoft. Administrative access to the servers, the databases and the cloud accounts is limited to named individuals.
4. Protecting information
- In transit: our apps connect to our services over HTTPS (TLS), with a certificate issued by a public certification authority.
- Files: signatures, photos, identity documents, contracts and pay stubs are kept in private cloud storage, encrypted at rest by the provider, and served only through signed links that expire — within an hour for photos and identity documents.
- Internal network: our databases, message queues and caches are reachable only from inside our private network, never from the Internet, and require their own credentials.
- Payments: card details are entered in PayPal's own fields and never reach our servers.
- Filing credentials: EFILE passwords, CSE passwords and access codes are used to transmit a return and are never stored.
- Bank connections: bank usernames and passwords are entered with the bank and Plaid, never with AuraTax. Before a bank is connected, the user confirms their identity with an authenticator-app code. Plaid's access tokens are encrypted with AES-256-GCM under a key kept apart from the database, each bound to its business and connection, are never sent to the apps, and are written to our database directly — never through our message queues or history.
- Backups: our databases are backed up every night to private, encrypted storage in Google Cloud's Montréal region, kept apart from our servers, by an account that can reach that storage and nothing else; each backup is deleted after 30 days.
- Secrets: passwords, keys and certificates must be kept out of source code, given only to the services that need them, and replaced whenever they may have been exposed.
5. The desktop app
On the desktop, returns, books and signatures stay on the user's computer, in the app's own data folder. The app's local credential store is encrypted with the operating system's protected storage (Keychain on macOS, DPAPI on Windows, the Secret Service on Linux) and checked for tampering. Protecting the computer itself — its sign-in, disk encryption and backups — is the user's responsibility.
6. Secure development and operations
- Changes go through version control and automated tests before they are released; releases are built from the reviewed source.
- Our services validate what they receive: the values a form accepts, who may write a record, and the signatures of the notifications payment providers send.
- Forms are protected against cross-site request forgery; the AI features answer signed-in users only and limit how many requests each may run at once; public forms are protected from bots; every page is served with headers that restrict framing, content sniffing and access to the camera, microphone and location.
- Testing runs against separate environments with their own data, never against production data.
- The software we depend on is kept up to date, and security updates are applied promptly.
- Our systems are monitored, and alerts are raised when a service fails.
7. Suppliers
We use suppliers that hold recognized security certifications for the services we rely on — Auth0, PayPal, Google Cloud, Mailgun — and give each only the information its service requires. The suppliers that process personal information are listed in our Privacy Policy.
8. Incident response
Anyone who suspects that information was lost, accessed or disclosed without authorization must report it to the Privacy Officer at once. We then:
- contain the incident and preserve what is needed to investigate it;
- assess the risk of harm to the people concerned;
- where there is a real risk of significant harm, notify them, the Office of the Privacy Commissioner of Canada and, for people in Quebec, the Commission d'accès à l'information, as soon as possible;
- record every incident in our breach register, whatever its outcome, and keep that record for at least 24 months;
- correct the cause, and review the measures in this policy.
9. Reporting a vulnerability
If you believe you have found a security vulnerability in AuraTax, write to support@auratax.ca with "Security" in the subject. Please give us a reasonable time to correct it before disclosing it, and do not access, change or delete data that is not yours while testing.
10. Review
This policy is reviewed at least once a year, and after any significant incident or change to AuraTax.