Security & your data

Built like the stakes are real.

Delvio handles the most sensitive data your office touches. It's protected accordingly — by a practicing CPA bound by the same IRS Pub 4557 and FTC Safeguards Rule obligations you are.

One rule governs this page: nothing here reads as live unless it is live. What's protecting your data today is written in the present tense; what ships with launch (October 2026) says so explicitly.

Protecting your data today

Encrypted in transit

All traffic between your browser and Delvio is encrypted over HTTPS/TLS. There is no unencrypted path to client data.

Encrypted at rest

All client data is stored encrypted. And because Delvio is web-based, there's no local client file sitting on an office PC waiting to walk out the door.

Your firm's data is yours alone

Every request is checked against your firm and the specific client being accessed. Firms are fully isolated from one another — your people see your clients, and nobody else's.

You own your data

Your client data belongs to your firm, not to us. You can export it — Delvio is not a place your practice gets locked into.

Report an issue instantly

Built-in one-click reporting routes problems straight to the people who fix them — including anything that looks like a security concern.

Committed for launch — October 2026

Delvio goes live for production use in October 2026. These protections are part of that launch, and none of them is optional or deferred beyond it.

  • Multi-factor authentication — required

    At launch, every login requires MFA. Not offered, not recommended — required, for every account, from day one of live use.

  • Full audit trail

    At launch, Delvio maintains a full audit trail: a record of who viewed and who changed each client record, and when.

  • SSNs walled off from the rest of the suite

    At launch, full Social Security numbers live only inside the tax engine, encrypted at the column level. The scheduler, check-in, and portal will have no access to them — by architecture, not by policy.

  • Backups with tested restores

    At launch, client data is backed up automatically and restores are tested on a schedule. A backup that's never been restored is a hope, not a plan.

  • Written incident-response plan

    At launch, Delvio operates under a written incident-response plan covering detection, containment, and the notification obligations your firm carries under the Safeguards Rule.

  • A security summary you can hand to anyone

    At launch, a plain-English customer security summary you can give a client, a partner, or a reviewer who asks how their data is protected.

Questions about security, or a specific requirement for your firm — a WISP review, a due-diligence questionnaire, an insurer's checklist? Get in touch. You'll be talking to the CPA who built it.