Security
How Agena Software protects the client tax information your firm prepares with us. Written for the security and vendor review that accounting firms carry out before trusting a provider with taxpayer data.
Last updated: October 5, 2026 • Agena Software LLC
Two-step verification on every account
Required for everyone. It cannot be turned off.
Encrypted in transit and at rest
HTTPS everywhere, and returns are encrypted before they are stored.
Stored in U.S. data centers
Client data and its backups stay in the United States.
Breach notice within 72 hours
Without undue delay, and within 72 hours of becoming aware of an incident affecting your data.
1. Sign-in and account security
- Required two-step verification. Every account signs in with a password and a code from an authenticator app, with single-use recovery codes for a lost phone. There is no setting to turn it off.
- Passwords. At least 12 characters, stored only as salted one-way hashes, never in readable form. Repeated failed sign-in attempts are limited.
- Password resets use a time-limited emailed link and also require the authenticator app or a recovery code. A reset signs the account out everywhere and sends a notice to the account’s email.
- Automatic sign-out after 30 minutes without activity, and after 8 hours in any case.
2. Encryption
- In transit: all traffic uses HTTPS, and browsers are told to accept nothing else (HTTP Strict Transport Security).
- At rest: saved returns, review snapshots and archived filing packages are encrypted by the application before they are written to the database.
- Backups are encrypted, and the encryption keys are kept separate from the backups.
3. Where your data is stored
Client data, including backups, is stored in data centers in the United States. Backups run nightly and expire within 90 days.
4. Who can see your firm’s data
- Your firm only. Returns belong to your firm. Members of your firm can see them; no other customer can.
- Roles and review. Owners and admins manage members; reviewers approve returns. Your firm can require that every return is reviewed, and that no one approves their own work.
- Activity log. Sign-ins, return access, approvals and downloads are recorded with dates and times. The log records identifiers, never client tax information.
- Agena Software. Access to production systems is limited to officers and employees of Agena Software LLC who need it to provide the tax preparation software and services.
5. Application and infrastructure security
- The preparation workspace runs on its own address (app.agenasoftware.com) and loads only our own code: no analytics, advertising or other third-party scripts, so nothing entered there is sent to outside services.
- A strict Content Security Policy, and protection against cross-site request forgery on every change.
- Servers are behind a firewall, with administrative access limited to approved locations, password logins to servers disabled, and blocking of repeated intrusion attempts.
- Security updates to the operating system are applied automatically, and the service is monitored for availability.
6. Payments
Payments are processed by Stripe. Card details go directly to Stripe; we never receive or store card numbers, and nothing we send to Stripe names your clients.
7. Incidents and breach notification
If an incident affects your firm’s data, we will notify your firm’s account owner without undue delay, and within 72 hours of becoming aware of it, with what we know, what we are doing, and what your firm may need to do.
8. Keeping and deleting data
Your firm can download its filing packages and workpapers at any time. How long we keep data, and how to have it deleted, is described in our Privacy Policy.
9. Your firm’s part
Security is shared. Your firm decides who joins its workspace and with what role, and should remove members promptly when they leave, keep authenticator devices and recovery codes safe, and protect the computers used to prepare and download returns. Filing packages you download are no longer protected by our systems.
10. Questions and reporting a vulnerability
For security questionnaires or questions from your firm’s review, or to report a suspected vulnerability, contact us at the address below. Please include the affected address and steps to reproduce, and do not access or change other people’s data while testing.
Email: support@agenasoftware.com