Skip to main content
Security

How this site handles what you send it.

A plain description of the actual architecture. We would rather state a narrow claim we can stand behind than a broad one we cannot.

Last updated · 26 July 2026Gulzari CPA LLC
01

Transport

The site is served exclusively over HTTPS. Connections negotiate TLS 1.3 where the client supports it and TLS 1.2 otherwise. HTTP requests are redirected. Certificates are managed and rotated automatically by the hosting platform.

02

What the diagnostic transmits, and when

The four-step diagnostic runs entirely in your browser. Your answers are held in client-side state as you move between steps, and nothing is sent to us until you submit the final step. If you close the tab before submitting, we never receive anything.

On submission the payload is sent over TLS to an API route on our own domain. It is stored so that we can prepare a response. It is not passed to any advertising, analytics, or enrichment service.

03

What we ask you not to send

This site is not a secure document channel. Do not send tax returns, bank or brokerage statements, passports, Social Security or ITIN numbers, EINs, or account credentials through the diagnostic or by email. If we need any of those, we will provide a secure channel once you are engaged.

04

Storage

Submissions are held in a managed Postgres database with encryption at rest and access restricted to the firm. Backups are managed by the database provider and are likewise encrypted. Retention is described in the privacy notice.

05

Hosting and processors

The site is hosted on Vercel and served from its edge network; the database is hosted on Neon. Both process data on our instructions. Requests are routed to the nearest available edge location, which for visitors outside the Americas generally means a region closer to them — but the origin and the database are in the United States, and that is where your data is processed.

06

Third-party code

The site ships no advertising tags, no session-recording tools, and no third-party analytics. Fonts are self-hosted rather than fetched from a font CDN, so loading a page does not disclose your visit to a third party.

07

Review mode

During a design review, a link may be issued that switches on an annotation toolbar for the recipient's browser. It is gated by a token in a strictly functional, HttpOnly cookie, it is visible only to holders of that link, and it collects nothing beyond the notes deliberately written into it. It is not present for ordinary visitors, and the token can be rotated to revoke every outstanding link at once.

08

Reporting a vulnerability

If you believe you have found a security issue, tell us before you tell anyone else. Send the details through the intake form marked as a security report, or use the address published at /.well-known/security.txt.

We will acknowledge a good-faith report and will not pursue action against research that avoids privacy violations, data destruction, and service degradation.

09

What we do not claim

No system is perfectly secure and we make no such claim. What we can say is what is written above: what is transmitted, when, to whom, and where it rests.