Security at SafeVault

SafeVault is built by AmitaSoft, LLC to hold documents people cannot afford to lose: tax records, identity documents, mortgage files, legal paperwork. This page sets out how that data is protected, which independent examination has been completed, and what is and is not covered.

SOC 2 Type 2

AmitaSoft, LLC completed a SOC 2 Type 2 examination of the AmitaSoft Software Application, which covers SafeVault, CliQloan and TaxFlo. The examination was performed by an independent licensed CPA firm for the observation period 15 May 2026 to 28 August 2026, and covers four Trust Services Criteria: Security, Availability, Processing Integrity and Confidentiality.

A SOC 2 Type 2 report examines whether controls were suitably designed and whether they operated effectively across the observation period, rather than at a single point in time.

The full report is confidential and available to prospective and existing customers under a non-disclosure agreement. Contact us to request it.

How data is protected

LayerProtection
Data in transit, externalTLS encryption for client-facing web applications and APIs
Data in transit, internalService-to-service communication within AWS, with network segmentation controls
Data at rest, databasesEncryption at rest on Amazon RDS
Data at rest, documentsServer-side encryption on Amazon S3
Data at rest, backupsBackup encryption under the Business Continuity and Disaster Recovery Policy
Access to dataRole-based access control through Keycloak, with multi-factor authentication required for critical systems
MonitoringLogging and monitoring under the Incident Management Policy

Access control

Authentication runs through a self-hosted Keycloak identity provider using OAuth 2.0 and OpenID Connect with PKCE. Access to systems and customer data is governed by role-based access control and AWS IAM, and multi-factor authentication is required for access to critical systems.

Access is provisioned through formal workflows on a documented business need, and reviewed on a defined periodic schedule. For multi-tenant deployments, customer data is logically separated to prevent cross-tenant access.

All employees, contractors and consultants execute non-disclosure agreements and acknowledge the Acceptable Use Policy before system access is granted.

Data classification

Data is classified into four tiers, and handling requirements follow the classification.

ClassificationWhat it covers
PublicWebsite content and marketing materials
Internal Use OnlyInternal policies and communications
ConfidentialEmployee records, financial reports, vendor contracts
RestrictedCustomer personal information, tax and mortgage documents, security logs

Social Security numbers are held as the last four digits only, with field-level protection.

Infrastructure

The platform runs on Amazon Web Services. Compute runs on EC2, ECS and Lambda; transactional data is held in Amazon RDS for PostgreSQL; documents are stored in Amazon S3; DNS is managed through Route 53; NGINX handles reverse proxy and routing; and CloudFront serves static frontend assets.

Application and infrastructure changes follow a documented process using GitHub for version control and GitHub Actions for continuous integration and deployment. Changes pass through a staging environment before production, and peer review of code changes is required before merge.

Testing and review

Independent and internal assessment during the examination period included a vulnerability scan in May 2026, an internal audit review documented in June 2026, and a full web application vulnerability assessment and penetration test in July 2026. The SOC 2 controls and Trust Services Criteria mapping was most recently updated in August 2026.

Incident response

Security events are logged and investigated under the Incident Management Policy. Remediation targets by severity are: critical within 7 days, high within 21 days, medium within 30 days, and low within 90 days or as approved by management.

Third-party services

SafeVault uses third-party providers for specific functions: Onfido for identity verification, and Stripe for billing. Within the wider AmitaSoft platform, CliQloan additionally uses DocuSign for electronic signature and Credco for credit data.

Cloud hosting and infrastructure are provided by a subservice organisation. Controls at that provider are complementary to AmitaSoft's own and were not within the scope of the SOC 2 examination.

What is not covered

We would rather be precise than impressive, so:

  • The SOC 2 examination covers Security, Availability, Processing Integrity and Confidentiality. It does not cover the Privacy Trust Services Criterion.
  • SafeVault is not HIPAA compliant and we do not offer a Business Associate Agreement. Do not use SafeVault to store protected health information.
  • SafeVault is not a zero-knowledge system. Documents are encrypted at rest using server-side encryption, and DocIQ reads document contents in order to classify and extract data. That capability is the product; it means AmitaSoft is technically able to access stored documents, subject to the access controls described above.
  • AmitaSoft maintains an internal availability target of 99.9%, excluding planned maintenance. This is an internal operational target and not a contractual service level.

Reporting a security issue

If you believe you have found a vulnerability in SafeVault, email support-safevault@amitasoft.com with the details. We will acknowledge and investigate under our Incident Management Policy.