Three things we won't trade away.
We handle some of the most sensitive data US businesses produce — TINs, SSNs, EINs, ledgers, and eventually accessibility records and product-testing data. Lose your trust on any of these and the model fails. That's how we make architecture decisions.
Privacy by default.
We collect the minimum data each service needs and delete it on the schedule you set. RBAC and least-privilege defaults across every role.
Security by construction.
AES-256 at rest, TLS 1.3 in transit, HSM-managed keys with automatic rotation. IRIS communication runs exclusively over A2A with idempotent submissions. SOC 2 Type II (in progress); ISO 27001 alongside.
Accuracy by design.
Tax filings aren't the place for probabilistic guesses. Our generation pipeline produces the same IRIS-ready XML for the same input, every time. AI is constrained, audited, and reviewed by humans on the edges.
Every new service inherits these three pillars on day one.
As we expand beyond tax — accessibility, excise, product testing — the control plane, audit trail, and data-handling rules don't change when the regulator does.
Compliance status
Certificate and link will appear here once the audit completes.
Aligned controls; same evidence base.
Authenticated and operational.
Contact
Security disclosures, questions, or audit requests. We respond to every report within 24 hours.
security@plaindot.com