Security & Trust

Built for the decisions CPA firms can't afford to get wrong

4impactdata protects the information your firm relies on with security and compliance built into the platform, not added on after the fact.

Trusted by CPA Firms & Outsourced Accounting Teams
AICPA SOC 2 Seal
Certified In Accordance With AICPA Standards
The AICPA is the national professional body and leading standard-setter for CPAs and the accounting profession.
Enterprise-Grade Protection

Security designed into every layer

From infrastructure to storage, 4impactdata is built to protect the information your firm relies on at every step.

Encryption in transit & at rest

Datastores are encrypted at rest, and secure protocols encrypt confidential and sensitive information whenever it moves over public networks.

Role-based access controls

Formal access control procedures and restricted firewall access keep information limited to verified credentials and approved connections.

Vulnerability & system monitoring

Formal policies govern vulnerability management and system monitoring, with intrusion detection systems in place across our infrastructure.

Data retention & disposal

Formal retention and disposal procedures guide the secure handling of information, and data is purged from the application environment when a customer leaves the service.

Data classification

A formal data classification policy helps ensure confidential information is properly secured and restricted to authorized personnel only.

Our Approach

Trust built into the platform, not added on after

Security, intelligence, and verification are treated as core parts of 4impactdata, not separate concerns.

01

Decision Intelligence, built in

4impactdata runs on a proprietary decision intelligence engine, built to help firms retain clients and grow revenue consistently, firm-wide.

02

Security by design

Encryption, access controls, and independent audits are part of how the platform is built, not steps added after the fact.

03

Verified, not just promised

Our Trust Center gives you direct access to our certifications and controls, so our security posture is something you can review for yourself.

Trust Center

Everything your security team needs, in one place

Our Trust Center gives your security, privacy, and procurement teams direct access to our certifications, controls, and compliance documentation, ready for your next vendor review.

Certifications & audit reports
SOC 2 Type 1 report and supporting compliance documentation
Full control listing
Infrastructure, organizational, product, internal, and data & privacy controls
Policies & documentation
Additional resources available on request for active security reviews
FAQ

Security & Compliance

Straightforward answers to the questions teams ask us most.

General

The company is SOC 2 Type 1 compliant. Our certification, audit report, and full list of controls are available through our Trust Center.

Beyond product security and data and privacy controls, the company maintains additional controls across infrastructure security, organizational security, and internal security procedures. Full details on these controls, along with certifications and policies, are available through our Trust Center.

Product Security

The company's datastores housing sensitive customer data are encrypted at rest.

The company performs control self-assessments at least annually to gain assurance that controls are in place and operating effectively. Corrective actions are taken based on relevant findings. If the company has committed to an SLA for a finding, the corrective action is completed within that SLA.

The company uses secure data transmission protocols to encrypt confidential and sensitive data when transmitted over public networks.

The company's formal policies outline the requirements for the following functions related to IT / Engineering:
  • vulnerability management;
  • system monitoring.
Data & Privacy

The company has formal retention and disposal procedures in place to guide the secure retention and disposal of company and customer data.

The company purges or removes customer data containing confidential information from the application environment, in accordance with best practices, when customers leave the service.

The company has a data classification policy in place to help ensure that confidential data is properly secured and restricted to authorized personnel.

This Website is Using Cookies

We use cookies to give you the best experience. By continuing to use our site, you agree to receive all cookies as described in our Privacy Policy.