Draft — not yet in effect
Security — draft
Drafting note
Not legal advice. Not reviewed by counsel. Draft v0.1 · 2026-09-24 · not yet published. Public page at
https://sidesheet.co/legal/security(/security). Drafting notes are in blockquotes; strip them before publishing.{{…}}= fill before publishing.The product is not built yet. Every "⚠️" note marks a control that must exist and be checked in production before this page goes live. The Terms (§4) and Privacy Policy (§5) make the same promises, so they are published together or not at all.
Sidesheet Security
Last updated: {{EFFECTIVE_DATE}}
Sidesheet holds your clients' business tax returns, which can include owners' Social Security numbers on K-1s. This page explains how we protect that data, in plain terms, for your vendor review. The binding promises are in our Terms of Service §§2, 4, 5 and 8.
Where your data is
- United States only. We process and store Customer Data only in the US.
- Hosting and AI: Google Cloud, region
us-central1(Iowa). - Database, sign-in, and file storage: Supabase, US region
us-west-2(Oregon).
Encryption
- In transit: TLS 1.2 or higher on every connection. Older versions are turned off.
- At rest: AES-256 encryption for the database, stored files, and backups.
- Upload and download links are signed and expire within minutes.
Drafting note
⚠️ Must be true in production before publishing. (TLS scan saved; at-rest encryption checked in each provider's console and screenshotted; signed-URL expiry set.)
Separation between customers
Each firm's data is walled off from every other firm's. The database itself enforces this, so a bug in our application code cannot show one firm another firm's files. We test this automatically on every change.
Drafting note
⚠️ Must be true in production before publishing. (Supabase row-level security on every business table, with automated leak tests in CI.)
Access by UNTAP LLC staff
Our staff do not look at your data except:
- when you grant support access for a specific issue, for the period you choose;
- when needed to investigate a security incident or keep the service running; or
- when the law requires it.
Every access is logged (Terms §4.2). If you turn on Help improve extraction (off by default), named staff may also review copies of your uploads with names, addresses and taxpayer ID numbers removed first. It never covers returns your firm prepared (Terms §2.4).
Drafting note
⚠️ Must be true in production before publishing. (Customer-granted, time-limited, logged support access; access logging for staff.)
Sign-in
- Multi-factor authentication (MFA) is required for every user by default: an authenticator-app code on every sign-in, including Google or Microsoft sign-in, enforced by the database, not only the app. A firm's administrator can make it optional for that firm (we warn them, record the change and email every administrator); anyone who has set one up must still use it at every sign-in.
- Sessions end after 8 hours without activity and after 24 hours at most.
- MFA is never reset by email alone: another admin of your firm, or we after confirming identity by phone, can reset it.
- Every UNTAP LLC staff account with production access uses MFA.
- Sign-in logs record time and IP address, not the contents of your files.
Drafting note
⚠️ Must be true in production before publishing. (Customer MFA; staff MFA on Google Cloud and Supabase.)
Retention and deletion
| Situation | What happens |
|---|---|
| While you are a customer | You choose how long source files and spreads are kept: 30 days up to 7 years. We delete them automatically at the end. You can delete any file or client sooner. |
| You close your account | You have 30 days to export. Then we delete your data from production systems. |
| Backups | Backups containing deleted data expire within a further 30 days. |
| Our logs | Logs never contain values from your returns and are kept at most 90 days. |
On request we confirm deletion in writing (Terms §5).
Drafting note
⚠️ Must be true in production before publishing. (Retention setting + automatic deletion job; per-file/per-client delete; backup expiry; PII-free logs with 90-day limit.)
Subprocessors
We use two: Google Cloud and Supabase. The full list, what each receives, and our 30-day change notice are at https://sidesheet.co/legal/subprocessors (Terms §8). How we use AI is explained at https://sidesheet.co/legal/ai.
If something goes wrong
If we confirm a security incident that resulted in unauthorized access to or disclosure of your Customer Data, we will tell you within 48 hours of confirming it. We will give you the information we have that you reasonably need for your own notification duties (Terms §4.4).
Drafting note
Drafting note: the incident playbook and customer notice template (legal-docs-plan §4) must exist before publishing, or the 48-hour promise is not realistic.
Reporting a vulnerability
Email security@sidesheet.co. We will reply within {{48 hours}}. Please do not test our
systems without written permission (Terms §3.6). Our contact details are also in
/.well-known/security.txt.
Drafting note
⚠️ Must be true in production before publishing. (security@ mailbox monitored; security.txt published — both are "new" in legal-docs-plan.)
Certifications
We have not completed a SOC 2 audit, ISO 27001 certification, or an independent penetration test. We will update this page if that changes (Terms §4.3). Until then, we answer security questionnaires honestly and in writing.
Questions
Security: security@sidesheet.co · Privacy: privacy@sidesheet.co · UNTAP LLC, {{MAILING_ADDRESS}}