Financial records are sensitive. Here is exactly how Sched3 protects them — no vague promises, just specifics.
Every layer of our stack is designed to keep your data private and tamper-proof.
All data stored in our database is encrypted with AES-256, the same standard used by banks and government agencies. Data in transit is protected with TLS 1.2+.
Every database query is scoped to the authenticated user. Your data is invisible to other users at the database level — not just the application level.
For accounting firms, each client is a separate taxpayer entity. Client A's data can never bleed into Client B's view, even within the same practice account.
API routes operate under the user's authenticated session. Elevated database access is reserved exclusively for billing webhooks and scheduled maintenance.
Sign in with email and password or Google OAuth, powered by Supabase Auth with secure session management.
Cloudflare Turnstile protects authentication forms from automated attacks without intrusive CAPTCHAs.
Multi-factor authentication is enforced on all production infrastructure access. Destructive actions require password re-confirmation.
When you generate a tax filing package, it needs to be exactly what you reviewed. We make sure of that.
Every filing artifact is checksummed at creation and re-verified at download. Any integrity mismatch is rejected before the file reaches you.
Client data collection uses single-purpose, time-limited URLs. There are no shared logins or permanent access tokens.
Sched3 never stores SINs, CRA login credentials, or RepIDs. Filing exports contain only the financial data needed for Schedule 3.
You should never feel locked in.
Export all your data — transactions, ACB records, filing packages — as CSV and PDF at any time from your settings.
Request account deletion with email confirmation. We cascade-delete all associated data, revoke active sessions, and clean up billing within 30 days.
We don't build commodity infrastructure from scratch. We rely on providers whose security is their business.
PostgreSQL database with AES-256 encryption at rest, SOC 2 Type II certified
Payment processing, PCI DSS Level 1 certified — the highest level of payment security
Application hosting and edge network, SOC 2 Type II certified
Bot protection and DDoS mitigation via Turnstile
Sched3 is built around Canada's Personal Information Protection and Electronic Documents Act. We collect only what's necessary, explain how it's used, and honour your right to access or delete it.
We are actively working toward SOC 2 Type II certification to provide formal, third-party assurance of our security controls.
We use a single session cookie for authentication. No tracking cookies, no cookie banners, no ad pixels.
For firms with specific data residency, compliance, or air-gapped requirements, Sched3 can be deployed within your own infrastructure. Contact us to discuss on-premise options.
Contact us