# AI Adoption Is Outrunning Security in Accounting. Here's How Kintsugi Is Built Differently

Canonical: https://trykintsugi.com/blog/kintsugi-ai-security
Published: 2026-07-29

Over half of accounting professionals now use AI, but many firms lack data guidelines to match. Here's how Kintsugi builds security into sales tax compliance.

AI is now part of day-to-day accounting work, from data management and
financial reporting to fraud detection. Adoption has moved quickly, but many
organizations have not created equally clear guidance for handling sensitive
financial data.

Sales tax compliance involves revenue by state, customer billing details,
exemption certificates, and a company's nexus footprint. Before trusting an
AI-powered platform with that data, teams should ask what happens to the data,
who can access it, how it is protected, and what happens if something goes
wrong.

## How Kintsugi approaches security

### Independently verified

Kintsugi maintains SOC 2 Type II certification, verified through annual
third-party audits against the AICPA Trust Services Criteria for security,
availability, processing integrity, confidentiality, and privacy.

### Data protection by default

Sensitive data is encrypted at rest using AES-256 and in transit using TLS 1.2
or higher. Authentication options include single sign-on, multi-factor
authentication, SAML 2.0, OAuth 2.0, and OIDC.

### Security in the product lifecycle

Kintsugi uses IT asset management, antivirus protection, access controls,
automated and manual security checks, and continuous logging and monitoring.
The platform runs on AWS with a multi-zone architecture and role-based,
least-privilege access.

### Privacy and resilience

Kintsugi maintains documented incident response and disaster recovery
processes, regular backups, and annual security training for employees. Data is
stored in regionally appropriate AWS locations, with customer rights around the
data lifecycle, including deletion.

## Questions to ask before adopting AI for tax data

- What is encrypted, and how?
- Who has independently audited the security claims, and when?
- Which authentication options are available?
- Is incident response documented and tested?
- What happens to the data when the customer leaves?

Sales tax compliance touches too much sensitive information to treat security as
an afterthought. Review Kintsugi's [security and privacy
commitments](/security-and-privacy) or talk with the team about data handling.
