SOC 2 Type II
Annually audited by an independent firm covering security, availability, and confidentiality.
Neo.Tax is obsessed with safeguarding your data in accordance with the industry’s highest standards of security and privacy.
Annually audited by an independent firm covering security, availability, and confidentiality.
Information-security management system certified to the international standard.
Compliant with EU data-protection regulations; DPA available for customers and partners.

Each environment is instantiated as a single-tenant Virtual Private Cloud — complete segregation of data, compute, and services. No infrastructure shared across tenants. Fully isolated at the network, application, and storage layers.
All Neo.Tax services — application, databases, storage — run in a dedicated environment instantiated per customer. No shared resources.
Approved security representatives can install network controls — custom firewall rules, IDS, outbound egress filtering — against the underlying cloud resources.
Support for customer-managed encryption keys (CMKs), including BYOK and other cloud-native KMS. Available upon request.
Full visibility into system-level activity via isolated logging, with optional export to your SIEM. Available upon request.
Optional private network connections (AWS Direct Connect, site-to-site VPN) and/or IP whitelisting — eliminating public-internet exposure.
Define your own backup schedules, maintenance windows, retention policies, and data-residency requirements at the infrastructure level.
On-premise control without sacrificing the elasticity, uptime, or automation of a modern cloud-native SaaS platform.
For security questionnaires, SOC 2 reports, or additional certifications, contact security@neo.tax or request via our Trust Center.