Security and your clients’ data
PRIA for Advisors reads a household’s tax return and prepares its Household Policy Review. This page says what happens to that return and to everything else your firm puts in.
The tax return
We read the PDF and then discard it. The file itself is never stored.
To read it, we send the return’s text to an AI model made by Anthropic, through Vercel’s AI Gateway. For a scanned return we send pictures of its first ten pages instead. Either way, the model sees everything printed on what it is sent. It reports the figures on named lines of the return. Our own code calculates the policy figures from those amounts, the household’s facts, and the law. Every request we send to a model is set to go only to providers that do not train on it.
We keep the figures, each with the line it came from, the names printed on the return, and the state from the home address. We do not keep Social Security numbers, bank account numbers or street addresses. If your firm discards a reading instead of saving it, the figures and names read from it are deleted.
Who handles the data
- Vercel hosts the app and our servers, and runs the AI Gateway.
- Neon runs our database.
- Trigger.dev runs background work, such as preparing household updates.
- Resend sends our email. Emails carry names, links and sign-in codes, never figures from a return.
- Stripe takes payment on its own page. We never see card numbers, and Stripe receives nothing about your clients.
- Anthropic and OpenAI models, reached through Vercel’s AI Gateway, read returns and help write notices and answers. Notices about a change in the law are drafted without client names.
The app itself carries no advertising or analytics trackers.
Encryption
Connections to the app are encrypted, and it tells browsers never to use an unencrypted one. On top of that, household facts, the figures read from returns and every document we deliver are encrypted one field at a time with AES-256. Each encrypted value is tied to its firm and its record, so a copy moved anywhere else cannot be read.
Each firm’s data stays separate
Access comes from your membership in your firm, checked on our servers for every request. The database enforces the separation as well: when the app answers a request, it reaches your firm’s data through a restricted database role that can see only your firm’s rows, a database feature called row-level security. A household’s upload link gives access only to sending its return to its advisor.
Signing in
Your staff sign in with a six-digit code we email to them. There are no passwords to steal or reuse. A code works for ten minutes and stops after five wrong tries, and codes go only to people your firm has added or invited.
Who can see what
Your firm gives each person a role: administrator, compliance, supervisor or advisor. Compliance can see every household but cannot manage people, settings or households. Only an administrator manages people and settings. Households send returns through their own upload links.
The record
An audit trail records who did what and when, including returns read and saved and changes to your firm’s settings. The database refuses to edit or delete an entry.
Public pages
A link an advisor sends a household works once, for 30 days. Uploads are limited in number per hour. A client’s review opens for the firm’s staff, signed in, or for the household after a six-digit code sent to the email the firm has on file; a household that answers its own link opens its review without a code for 30 days. The free Household Policy Review builder offers a share link for each completed report.
What we have not done yet
- We do not yet have a SOC 2 report or an independent penetration test.
- Sign-in does not yet offer a second factor, such as a passkey or an authenticator app, or single sign-on.
- Requests to AI models are not yet limited to providers that keep no copy, and we have not yet published those providers’ retention terms.
- We have not yet rehearsed a full restore from backup.
Our Enterprise Subscription Terms set out our security commitments, including when we tell you about an incident. Questions go to legal@policyrisk.com.