Security and trust
Security at TakePublic
Draft filings can contain inside information the market has not seen, so security is designed into the filing workflow, not added around it.
- Hosting
- Cloudflare edge, filing documents in two regions
- Encryption
- In transit and in storage
- Access
- By role, with a second sign-in step
- Audit trail
- Recorded in order, cannot be rewritten
- Subprocessors
- 11 services, full list
- Contact
- security@takepublic.com
Encryption and secrets
Your EDGAR codes and accounting connections are encrypted before they are stored, and every connection to TakePublic is encrypted.
- EDGAR filer codesYour EDGAR codes, including the CCC, are encrypted before they are saved. They are never stored in readable form.
- The key is kept apartAccounting connections are protected the same way. The key that unlocks them is held in a separate vault, and if it is ever unavailable the system stops rather than carry on unprotected.
The audit trail
Every action is recorded in order. Nothing in the record can be changed or removed, and we check it every day.
- Nothing removedThe record only grows. Entries cannot be edited or deleted, and we verify the whole record every day.
- Each entry sealed to the lastEvery entry carries a fingerprint of the one before it, all the way back to the first.
- Tampering showsChange one entry and every later fingerprint stops matching, so the alteration is visible.
The counsel gate
No filing prepared in TakePublic reaches EDGAR until your securities attorney has signed off on the exact document that will be sent.
- 01Version fixed
- 02Counsel signs it
- 03Checked again at send
- 04Sent as signed
- Version fixedThe document is frozen. For a 10-K or 10-Q that includes the full tagged package.
- Counsel signs itYour securities attorney's sign-off applies to that version and no other.
- Checked again at sendRight before transmission the package is rebuilt and compared. Any difference holds the filing.
- Sent as signedEDGAR receives exactly what counsel signed.
- The signature follows the documentAny edit changes the document, so the earlier sign-off no longer applies and the filing has to be reviewed and signed again.
- No gap between signing and sendingSigning, editing and sending are handled as one uninterrupted sequence, so the version that was signed is the version that is sent.
- The signature covers the tagged packageFor a 10-K or 10-Q, the Inline XBRL package is frozen before review, counsel signs that package, and EDGAR receives it unchanged.
- Profile changes cannot slip past itBefore sending, the package is rebuilt and compared with what was signed. A company profile change that alters the output holds the filing until it is signed again.
Access and authentication
Each person sees only the work their seat is for, and draft filings are handled as inside information.
- A second sign-in stepAttorneys and platform administrators must confirm each sign-in with a code from an authenticator app or a text message. Anyone else can turn it on.
- Filing content cleaned of hidden codeText that people or the AI add to a filing is stripped of anything that could run as code, once before it is saved and again before it is shown.
Record retention
Signed records, attestations and the audit log are kept for as long as TakePublic provides the Service and at least seven years, longer than the five years Rule 302(b) of Regulation S-T sets for signed filing records.
- Kept for as long as we provide the ServiceTakePublic keeps signed records, attestations and the audit log for as long as it provides the Service, and in any case for at least seven years after a record is made and, for an attestation, at least seven years after the signer's most recent electronic signature through the Service. They are not deleted when an account, subscription or workspace ends, or in response to a request to delete personal information. A filing document removed from storage is recoverable for 30 days.
- Independent replicaFiling documents are held in two regions and replicated to a second, independent provider, with a further copy taken when a filing is finalized. The database restores to any point in time.
- Access is recordedEvery read of a stored secret and every access to a filing document is recorded, separately from the audit trail described above.
- Every version keptSaving over a filing document retains the earlier version instead of replacing it, so the record shows what counsel signed and what changed after.
AI and your data
Your books and filings are never used to train AI models. Anthropic provides the drafting model.
- Connections stop rather than guessIf an accounting, email, text-message or EDGAR connection is set up wrong, the affected action stops instead of proceeding. Nothing quietly falls back.
Integrations and vendors
8 outside services run the product, each for one stated purpose.
- Cloudflare Edge Delivers the site, blocks attacks, and holds an offsite backup copy.
- QuickBooks Books QuickBooks Online connection.
- Stripe Billing Subscription billing.
- Postmark Email Email notifications.
- Twilio SMS Text-message notifications.
- Google Cloud Identity Platform Sign-in Sign-in and passwords.
- Anthropic AI AI drafting and filing chat model.
- OpenAI AI Support chat model and retrieval embeddings.
Every service that handles customer data, including error monitoring and analytics, is listed with its purpose on the subprocessors page.
Compliance status
SOC 2 in preparation; not yet certified. Documents on request under NDA.
Control status is monitored continuously and published on the TakePublic Trust Center, where documents can be requested under NDA. Both policies are with an A-rated carrier, effective September 1, 2026; certificates of insurance are available to customers on request.
Implemented in the product today
- Every connection encrypted
- Secrets encrypted in storage
- Access limited by role
- Second sign-in step
- Counsel signs before filing
- Filing content cleaned of hidden code
- Record cannot be rewritten
- Signed records kept for as long as we provide the Service and at least seven years
Security articles in the help center
The step-by-step detail behind this page: data protection, the audit trail, and the second sign-in step.
Frequently asked questions
How are EDGAR filer codes protected?
Your EDGAR codes, including the CCC, are encrypted before they are saved and are never stored in readable form. The key that unlocks them is held separately, and if it is ever unavailable the system stops rather than carry on without protection.
Can a filing be submitted without a sign-off?
Not a filing prepared in TakePublic: it reaches EDGAR only after a sign-off on the exact version being sent, by the reviewer your company designates for a Form 3, 4 or 5 or by your securities attorney for any other filing, and any later edit holds the filing until they sign again. A Form 3, 4 or 5 uploaded as already reviewed and signed files exactly as uploaded, after the company attaches the signed page and attests to its review.
Does TakePublic train AI models on customer content?
No. Your books and filings are never used to train AI models, and draft filings are treated as inside information that only the people whose role needs them can see.
What is TakePublic's SOC 2 status?
TakePublic is preparing for SOC 2, with control status monitored continuously on the TakePublic Trust Center. Certification has not been completed, and this page does not represent otherwise.
TakePublic is a technology platform, not a law firm, broker-dealer, or auditor. Forms 3, 4 and 5 prepared in TakePublic file only after the reviewer the company designates, such as its securities counsel, signs off; any other filing prepared in TakePublic files only after a licensed securities attorney signs off.