W
WriteOffOS
← Back to home

How we protect your data

WriteOffOS handles sensitive tax and financial documents. Here is exactly how your information is isolated, encrypted, and kept visible only to you and the tax professional you authorize.

Isolated to your account

Every request is scoped to your firm. Another customer cannot query, list, or reach your clients, documents, or analyses — isolation is enforced on the server for every read.

Your uploads aren't served over the web

Uploaded documents are stored under a private, randomly-named path per client and are never exposed through a public or guessable URL. Their contents are read only to generate your analysis.

Encrypted in transit and at rest

All traffic is served over TLS (HTTPS). Data stored on disk and in the database is encrypted at rest at the infrastructure layer (Microsoft Azure).

Mandatory two-factor authentication

Every account requires app-based two-factor authentication (TOTP) in addition to a password. Passwords are hashed with bcrypt and never stored in plain text; sign-in is rate-limited.

Who can see your data

Only you, the users you add to your own account, and any tax professional you explicitly share with can see what you upload and what WriteOffOS generates. Client portal links are single-client, expiring access tokens — they only reveal that one client’s analysis, and only after it has been approved for release.

WriteOffOS staff do not browse customer documents as part of normal operation. Access to production systems is restricted and role-based.


Sub-processors

We use a small number of vetted providers to operate the service. Each is bound by its own security and privacy commitments:

  • Anthropic (Claude): document text is sent to Anthropic to generate analysis. On our API tier, submissions are not used to train models by default.
  • Plaid: optional bank-transaction import. Your banking credentials are entered with Plaid and are never shared with WriteOffOS.
  • Stripe: payment processing. We never see or store your full card number.
  • Microsoft Azure: hosting and encrypted-at-rest storage.

Your control

You own your data. You can request an export or deletion of your account and its documents at any time — see the Privacy Policy for retention periods and how to exercise your rights. Uploaded documents tied to a deleted account are removed within 90 days.


Honest scope

We believe in telling you what we have and what we don’t. WriteOffOS applies the controls described above today. We have not yet completed a formal SOC 2 audit or a third-party penetration test; when we do, we will say so here rather than imply it beforehand. If your organization requires specific security documentation before onboarding, contact us and we will share what we can.


Report a concern

Found a security issue, or have a question before you upload anything?

WriteOffOS — Security
security@writeoffos.com

© 2026 WriteOffOS. All rights reserved. · Privacy Policy · Terms of Service · Disclaimer