Security
Filing on someone's behalf is a position of trust. Here is what we actually do, in terms you can check.
Signing credentials are never stored
A signer types their EFAST2 User ID and PIN on the signing screen. They are used once to build the signed return, transmitted, and then gone: no database column holds them, no log line records them, and the copy of the filing we keep has both halves masked. Signing and filing are one step for exactly this reason — a stored signed return would carry a live credential.
No passwords
You sign in with a six-digit code emailed to you. There is no password for us to lose, for you to reuse, or for anyone to find in a breach dump. Codes last ten minutes, work once, allow five attempts, and are stored only as a fingerprint.
Separation of duties
An organisation decides who prepares returns, who signs them, and who may only read. A preparer cannot file; a signer cannot change the answers. And the signer role only opens the signing screen — what actually signs is that person's own government credentials.
What we keep, and prove
Every filing carries an append-only history: who prepared it, what the checks said, who signed it, what was transmitted, and what the Department replied. That record is what our certification affidavit turns on.
The plumbing
- TLS everywhere; strict transport security; encrypted storage.
- Attachments are virus-scanned before anything is transmitted — the engine refuses to transmit if no scanner is available.
- Nightly encrypted database backups, kept a year, and a restore that has been tested.
- No advertising or analytics networks, so nothing about your filings leaves for a third party.
Telling us about a problem
If you find a security issue, email 5500api@claydesk.com with enough detail to reproduce it. We will reply, fix it, and credit you if you would like.