Security at Rumo
Last updated: June 2026
We treat your firm's data and your clients' data with the care that the CPA profession demands. This page summarizes the controls we have in place today.
Encryption
- TLS 1.2+ for all data in transit.
- AES-256 encryption at rest for documents and database storage.
- Encrypted backups in a separate region.
Access control
- Role-based access for every seat — firm admin, preparer, reviewer, and client.
- Multi-factor authentication available for all users; required for admin roles.
- Recovery codes for safe account recovery.
Audit and monitoring
- Admins can review every meaningful action — sign-ins, role changes, billing events.
- Continuous infrastructure monitoring with alerting for anomalous activity.
Data isolation
Each firm's data is logically isolated. Access is gated by row-level security policies, and service-role keys are restricted to trusted server-side code paths.
Compliance alignment
Our controls are aligned with the FTC Safeguards Rule, IRS Publication 4557, and the principles in SOC 2. We are pursuing formal SOC 2 Type II attestation during pilot.
Incident response
Suspected security incidents trigger our internal response playbook. We notify affected customers without undue delay and in line with applicable law.
Reporting a vulnerability
Found something? Please write to security@rumopro.com. We acknowledge reports within one business day.