Security at Rumo

Last updated: June 2026

We treat your firm's data and your clients' data with the care that the CPA profession demands. This page summarizes the controls we have in place today.

Encryption

  • TLS 1.2+ for all data in transit.
  • AES-256 encryption at rest for documents and database storage.
  • Encrypted backups in a separate region.

Access control

  • Role-based access for every seat — firm admin, preparer, reviewer, and client.
  • Multi-factor authentication available for all users; required for admin roles.
  • Recovery codes for safe account recovery.

Audit and monitoring

  • Admins can review every meaningful action — sign-ins, role changes, billing events.
  • Continuous infrastructure monitoring with alerting for anomalous activity.

Data isolation

Each firm's data is logically isolated. Access is gated by row-level security policies, and service-role keys are restricted to trusted server-side code paths.

Compliance alignment

Our controls are aligned with the FTC Safeguards Rule, IRS Publication 4557, and the principles in SOC 2. We are pursuing formal SOC 2 Type II attestation during pilot.

Incident response

Suspected security incidents trigger our internal response playbook. We notify affected customers without undue delay and in line with applicable law.

Reporting a vulnerability

Found something? Please write to security@rumopro.com. We acknowledge reports within one business day.