AI is now part of day-to-day accounting work, from data management and financial reporting to fraud detection. Adoption has moved quickly, but many organizations have not created equally clear guidance for handling sensitive financial data.
Sales tax compliance involves revenue by state, customer billing details, exemption certificates, and a company's nexus footprint. Before trusting an AI-powered platform with that data, teams should ask what happens to the data, who can access it, how it is protected, and what happens if something goes wrong.
How Kintsugi approaches security
Independently verified
Kintsugi maintains SOC 2 Type II certification, verified through annual third-party audits against the AICPA Trust Services Criteria for security, availability, processing integrity, confidentiality, and privacy.
Data protection by default
Sensitive data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher. Authentication options include single sign-on, multi-factor authentication, SAML 2.0, OAuth 2.0, and OIDC.
Security in the product lifecycle
Kintsugi uses IT asset management, antivirus protection, access controls, automated and manual security checks, and continuous logging and monitoring. The platform runs on AWS with a multi-zone architecture and role-based, least-privilege access.
Privacy and resilience
Kintsugi maintains documented incident response and disaster recovery processes, regular backups, and annual security training for employees. Data is stored in regionally appropriate AWS locations, with customer rights around the data lifecycle, including deletion.
Questions to ask before adopting AI for tax data
- What is encrypted, and how?
- Who has independently audited the security claims, and when?
- Which authentication options are available?
- Is incident response documented and tested?
- What happens to the data when the customer leaves?
Sales tax compliance touches too much sensitive information to treat security as an afterthought. Review Kintsugi's security and privacy commitments or talk with the team about data handling.


