Hosted Web Servers
SurePrep Production servers are housed in SSAE-16 certified Internet Data Centers located in the continental US. The SurePrep infrastructure uses State-of-the-art firewall and intrusion detection technology to achieve a high level of security. Servers and firewall are monitored on a 24/7 basis. Performance reports are generated to assure maximum operational availability. Server load-balancing and distributed architecture are in place to achieve the high performance and availability.
Facility Security
• Regulated, monitored access
• Biometric palm scanners
• Individual card key access
• Digital recordings and video storage
Environmental Control
• Static free environment
• 24 X 7 NOC personnel presence
• Fire suppression systems
Network Operations Center
• Permissively neutral network
• Dual path, dual entrance fiber facilities
• Complete redundancy
Building Power
• Continuous, uninterrupted operation
• N + 1 dual fed redundancy
Certifications
• SSAE-16 certifications; annual reviews of internal controls are performed by independent auditors.
SurePrep Tax Center
The SurePrep Tax Center is a Microsoft SQL based ASP application. Password protected logins restrict access to registered users. User passwords are encrypted in the SQL database and a log is maintained of all users that access the system. The SurePrep Tax Center uses 128-bit Secure Socket Layer encryption for all data transfers. This is the same encryption technology used by banks for securing online banking transactions.
Non-disclosure / Confidentiality Agreements
All SurePrep employees in the U.S. and India are required to sign non-disclosure/confidentiality agreements. Each employee is bound by the agreement and not allowed to discuss information from engagements they are working on with anyone unless there is a question related to the preparation of the engagement. Preparers and reviewers are only allowed to request help from their direct supervisors.
Service Centers
SurePrep has implemented a comprehensive service center security policy that is designed to ensure the protection of data. Security measures include policies that:
1. Restrict physical access to the processing and server environments.
2. Ensure a paperless environment so data cannot be removed from the facility.
3. Standard computer hardware and software configurations restrict access to email and Internet sites. Medialess computers ensure files cannot be copied.
4. Thin clients are used with centrally managed servers. No data ever resides on the diskless thin client, and provide only keyboard, video and mouse input.
5. PC-based workstations do not have CD or floppy drives and USB ports are disabled.
Certifications
• SurePrep is ISO 9001:2008 Certified.
Physical Security
• A security guard is stationed at the entrance.
• Access card required to enter the facility.
• Access card required to enter the server room. Access is restricted to the IT and service center manager.
Paperless Environment
• Returns are prepared in a paperless environment. No source documents or tax returns are printed.
• The printer in the server room is limited to printing management reports
• Paper shredders are used by management to shred management reports
Personal Belongings
• Briefcases and other personal belongings are not allowed in the service center
Hardware
•There are no removable media devices. PC harddrives are read only.
Internet Access
• No access to email
• Outlook and Outlook Express have been removed from all PC’s
• No access to internet except for:
o SurePrep site for return processing
o Global fx site for return processing
o GoSystem RS site for return processing
o RIA Checkpoint access is allowed for supervisors only