Security & Trust

Your clients' data, and how we hold it

You are accountable for the data your clients give you, and that accountability follows it to every vendor you use. This page is written so you can document us properly, including the parts we have not built yet.

Why you need this from us

Under the FTC Safeguards Rule, tax and accounting practices are treated as financial institutions regardless of size. IRS Publication 5708 puts it plainly: the law requires you to have a written information security plan, and that plan has to account for the providers who handle your clients' information.

That means someone will eventually ask you what Journey does with your data. The answers are below, in the shape your plan needs them.

Journey firms can also generate a draft of that plan from their own settings, filled in from what Journey already knows about their access controls and their team.

What we do

Your firm's data is isolated in the database itself

Every record is scoped to your firm and enforced by row-level security at the database layer, not by application code that could be bypassed. A member of one firm cannot query another firm's records, and a client's portal session can only ever reach their own.

Two-factor authentication is required for staff, not offered

Every staff account must enroll an authenticator app before reaching the application, and is challenged for it at sign-in. Sensitive actions re-challenge. It is not a setting someone can leave switched off.

Access follows the role you assign

Owner, general manager, manager, supervisor and staff each reach a different set of actions, enforced on the server rather than by hiding buttons. Deactivating someone removes their access immediately, in the database.

Clients get a second step too, not just staff

Signing in to your portal emails the client a six-digit code, which they enter before reaching any documents. It is on for every firm by default. An owner can switch it off in Settings if their own security plan calls for something different.

Changes are logged, and the log is kept

Changes to client records are written to an audit log retained for 24 months, so you can answer what happened, when, and who did it. Documents are served through time-limited links rather than public URLs.

Client information is encrypted in transit and at rest. Our full commitments, and the list of providers we rely on, are in the data processing addendum.

What happens to your data when AI is involved

Journey uses AI to draft client emails, sort inbound mail, summarize a client's history, and read handwriting off returned paper questionnaires. Those features send the relevant content to OpenAI.

Data sent to the OpenAI API is not used to train their models and is not retained for logging, but is held for up to 30 days for abuse monitoring. We tell you that precisely because it is the detail a careful reader will ask about.

Scanned documents are included when a firm uses document reading, so a firm that would rather not send document images to a third party should not enable it.

What we do not have

No SOC 2 report

Journey does not hold a SOC 2 report today. We would rather tell you that than imply otherwise. The controls described above are real and you are welcome to verify them; they are simply not yet attested by an outside auditor.

Found something, or need more detail?

If you believe you have found a security issue, tell us and we will look at it straight away. If you are filling in a vendor assessment and need something this page does not cover, ask and we will answer it properly rather than send you a brochure.

Read the DPA

Last reviewed September 2026