How your business data is handled.
Described in terms of what the systems actually do. There are no certification badges on this page, because BKS does not hold certifications it has not earned and will not imply otherwise.
In BKS Suite
Platform controls
Businesses are isolated from each other
Separation between businesses is enforced in the database with row-level security, not by a filter in the application. A query that forgets a WHERE clause still cannot return another business’s rows.
Access is per person and per role
Users are granted access to specific businesses with a role that determines what they can see and do. An outside accountant or a bookkeeper gets their own scoped account rather than sharing a password.
Actions are logged and reviewable
BKS Suite keeps an append-only audit log of user actions, and the accounting ledger itself is append-only: corrections are posted as entries, never as silent edits to history.
Sensitive fields are encrypted
Employee personal data in payroll is encrypted at rest, and authentication uses hashed credentials with rotating refresh tokens and optional time-based multi-factor authentication.
On this website
What bks.agency itself does
- This website sets no advertising cookies and runs no advertising scripts. It measures page visits and a short list of actions through Google Analytics, which never receives anything you type into a form.
- Google Analytics is the only third party this site loads. A Content Security Policy is served that names it explicitly and blocks every other external script, font, and asset.
- Traffic is served over HTTPS with HSTS, and standard hardening headers are set on every response.
- The public assistant has no access to any customer record. Every tool available to it reads published service information stored in the website itself.
- The contact form collects only name, business name, email, phone, the service you selected, and what you wrote. It does not accept and must never be used for an SSN, EIN, or financial account number.
Assistant
What BKS AI is allowed to do
The assistant on this website is read-only. Every tool it can call reads published service, industry, and deadline information from this site’s own source. There is no database connection, no authenticated session, and no write path available to it, so a conversation here cannot reach a customer record regardless of what is typed into it.
Inside BKS Suite the assistant works within your business and cannot exceed the permissions your own user already has. Anything that would change data follows a prepare, confirm, execute sequence: the action is prepared, the exact change is shown to you, and it runs only after you confirm. Each step is recorded in the audit log against your user.
Do not send an SSN, EIN, bank account, or card number to the assistant or through the contact form. Sensitive information is collected inside your authenticated account or by your coordinator.
Reporting
Found a security problem?
If you believe you have found a vulnerability in this website or in any BKS system, email TEAM@BKSTAX.COM with the subject line “Security”, or call 732-634-9800. Please include enough detail to reproduce it, and give us a reasonable opportunity to fix it before disclosing it publicly.
See also our privacy notice for what data this site collects and why.
Questions about how we would handle your data?
Ask before you commit. We will tell you exactly where your information lives and who can see it.
Prefer to write it out? Send us the details.