Security and trust

Security at TakePublic

TakePublic handles draft SEC filings, books data, and EDGAR filer codes. Draft filings can contain material nonpublic information, so security is designed into the filing workflow, not added around it.

TRUST
TakePublic TP-SEC Security controls Designed for filing workflows
Traffic
TLS for all traffic
Secrets
AES-256-GCM before storage
Audit record
Append-only and hash-chained
Submission
Exact-hash counsel sign-off required

Data protection

Encryption and secrets

All traffic uses TLS. Sensitive filing credentials and connected-account tokens receive an additional control before storage.

EDGAR filer codes

EDGAR filer codes, including the CCC, are encrypted with AES-256-GCM before storage. They are never stored in plaintext.

Production key handling

Integration OAuth tokens use the same encryption before storage. The 256-bit key is KMS-backed in production, and the system fails closed if the key is missing.

Evidence

The audit trail

Every filing transition, sign-off, content edit, integration sync, and admin action writes an audit event.

Submission control

The counsel gate

No filing reaches EDGAR submission without your securities attorney's sign-off that matches the exact document hash.

The signature follows the document

A content edit changes the document hash. The prior sign-off no longer matches, so the filing must be reviewed and signed again.

The gate is transactional

Sign-off, content edits, and submission run transactionally with row locks, keeping the signed version and submitted version aligned.

Least privilege

Access and authentication

Role-based access limits counsel and auditor seats to what their work requires. Draft filings are treated as MNPI, and access-relevant actions are recorded in the audit trail.

Multi-factor authentication

TOTP multi-factor authentication is required in production for counsel and platform admin roles. It is available to every role.

Sanitized filing content

User-supplied and AI-generated HTML is sanitized on the server and again in the client before rendering.

Model boundaries

AI and your data

Customer books and filings are not used to train AI models. Anthropic serves the drafting model.

Integrations fail closed

If an accounting, email, SMS, or EDGAR connection is misconfigured, the affected action stops instead of proceeding. No silent fallbacks.

Connected systems

Integrations and vendors

These services connect to TakePublic or process data for the stated purpose.

Books

QuickBooks

QuickBooks Online OAuth sync.

Billing

Stripe

Subscription billing.

Email

Postmark

Transactional email.

SMS

Twilio

SMS notifications.

Auth

Google Cloud Identity Platform

Production authentication.

AI

Anthropic

AI drafting model.

Current posture

Compliance status

TakePublic is on the SOC 2 track, and preparation is underway. Certification has not been completed. The controls described on this page are the controls implemented in the product today.

Diligence questions

Security FAQ

How are EDGAR filer codes protected?

EDGAR filer codes, including the CCC, are encrypted with AES-256-GCM before storage and are never stored in plaintext. In production, the 256-bit encryption key is backed by KMS. If the key is missing, the system fails closed instead of continuing with unprotected secrets.

Can a filing be submitted without counsel sign-off?

No. A filing cannot reach EDGAR submission without sign-off from your securities attorney that matches the exact document hash. Sign-off, content edits, and submission run transactionally with row locks. If the document changes, the signed hash no longer matches and the gate blocks submission.

Does TakePublic train AI models on customer content?

No. Customer books and filings are not used to train AI models. Anthropic serves the drafting model. TakePublic treats draft filings as material nonpublic information, limits access by role, and records access-relevant actions in the append-only, hash-chained audit trail for a verifiable record.

What is TakePublic's SOC 2 status?

TakePublic is on the SOC 2 track, with preparation underway. TakePublic has not completed certification, and this page does not represent otherwise. Current product controls include TLS, encrypted secrets, role-based access, multi-factor authentication, a counsel sign-off gate, HTML sanitization, and an append-only, hash-chained audit trail.

Go deeper

Security articles in the help center

The operational detail behind this page: data protection, the audit trail, and multi-factor authentication.

01
TakePublic Help 01 How TakePublic protects your data Encryption, least privilege, MNPI policy, and no training on your content.
02
TakePublic Help 02 Audit trail Append-only, hash-chained log of material actions.
03
TakePublic Help 03 Multi-factor authentication Required for counsel and platform admin. TOTP enrollment in Settings.

Two more documents for your review

The privacy policy explains how TakePublic handles personal information. The full help collection covers every security control in operational detail.

Privacy policy All security help

TakePublic is a technology platform, not a law firm, broker-dealer, or auditor. Nothing files without review and sign-off by a licensed securities attorney.