Skip to main content
Next expat filing deadlineCheck my situation

Trust

How we protect your data

Your tax-return inputs, the statements you upload, and your payment details are the most sensitive things you can hand a piece of software. Here is, in plain terms, which safeguards the product applies. No system can guarantee absolute security.

Documents you upload

Statements, prior returns and holdings files go to private storage over an encrypted connection — never by email attachment. They are served back only through access-controlled routes tied to your case (no public links), every file is scanned before it can be opened, and access to a case file by staff is audit-logged. Upload and delivery links, where a case uses them, are single-purpose tokens that expire; the raw token never appears in an email or a log.

Payments handled by Stripe

When you pay for a package or an engagement, Stripe processes the payment on its own hosted page. We receive only the resulting Checkout Session id and the amount — we never see or store your card number. One payment, no subscription; the price is shown before you leave Atamatax.

Brokerage data

Upload a year-end positions CSV or a brokerage statement; holdings are screened by ticker and ISIN with the source shown per holding.

Brokerage data is imported from the statement or positions CSV you upload. A read-only Plaid connection for US brokerages is built and will open once Plaid's production review completes. When it opens it will be a read-only connection: your broker login will go directly to Plaid, never to us, and Atamatax will never move money in or out of an account. This page will say so on the day it is live.

Transport and application-layer safeguards

The application sets HSTS and upgrades insecure requests. Transport encryption is provided by the active hosting and sub-processor configurations. Sensitive fields — social-security numbers and any brokerage access token — are additionally encrypted at the application layer with AES-256-GCM before they ever reach the database, so they are stored as ciphertext rather than plain text.

Production database access is restricted to two server-side keys, and those service-role keys never reach the browser. Case and return data live in a US-hosted Postgres database with row-level security on every table; the case tables are reachable only through server routes that check who you are first. Backup availability and retention depend on the active provider configuration; this page does not promise a specific backup window.

We never sell your data

We do not sell your personal information to advertisers, data brokers, or any third party. The only parties who touch your data are the sub-processors that run the service (such as Supabase, Vercel, Stripe, and Resend), each acting under its own data-processing agreement, and — on an engagement that includes one — the independent credentialed professional assigned to your case, who sees the case file for that engagement only.

Delete your data whenever you want

You can request a copy of your data, ask us to correct it, or ask us to delete it. Email support@atamatax.com from the address on file and we respond within 30 days. Account credentials are deleted within 90 days after you ask us to close your account. Full details are in our Privacy Policy.

If something goes wrong

No system is perfect. If we discover a security incident affecting your data, we will notify you within 72 hours of confirming the incident and publish a post-mortem on the same domain.


Security researcher? Read our responsible-disclosure policy and report an issue: Report a security vulnerability → · Researchers we've credited