is engineered to meet the security and compliance demands of U.S. CPA firms handling sensitive client financial and tax data.
🔐
AES-256 Encryption at Rest
Every file, record, and data point stored in CPApex is encrypted using AES-256 — the same standard used by the U.S. government and financial institutions.
🔒
TLS 1.3 In-Transit Encryption
All data moving between your browser and CPApex is protected by TLS 1.3, preventing interception or eavesdropping on every request.
🏅
SOC 2 Type II Infrastructure
CPApex is hosted on SOC 2 Type II certified cloud infrastructure, with continuous monitoring, availability guarantees, and third-party security audits.
👤
Role-Based Access Control
Granular, 4-tier permission system (Owner → Admin → Staff → Client). Every user sees only what they need — nothing more.
📋
Full Audit Trails
Every login, document access, invoice change, and settings edit is logged with timestamp, user, and IP address — ready for your compliance reviews.
📱
Multi-Factor Authentication
Protect every account with MFA. CPApex supports authenticator apps and email-based verification to prevent unauthorized access.
🏥
HIPAA-Ready Architecture
Built with healthcare-compliant data practices, making CPApex suitable for medical practice clients and multi-discipline advisory firms.
⏱️
Automatic Session Timeouts
Inactive sessions are automatically terminated to prevent unauthorized access on shared or unattended devices.
✍️
Secure E-Signature
EngageDocs uses cryptographically signed, timestamped signatures — legally binding and tamper-evident for engagement letters and tax returns.