Security

Controls you can review.

What protects your account and your research today, stated plainly. We list only what Virtus actually does.

Hosting and connections

Hosted on Cloudflare
Virtus runs on Cloudflare’s network at virtusprofessionalservices.com.
Encrypted connections
Pages are served over HTTPS, and your browser is told to use only HTTPS for this site for the next year.
Browser security policies
Other websites cannot embed Virtus pages. Browser security policies restrict which resources the site may load.
Protected account and workspace changes
Browser requests that change your account or workspace require an allowed request origin and an authorized session. Provider callbacks are validated separately.

Accounts and workspace access

A protected sign-in cookie
Your sign-in is kept in one signed cookie that page scripts cannot read (HttpOnly), that travels only over HTTPS (Secure), and that limits when it is sent with requests from other sites (SameSite=Lax). It ends after 30 minutes without activity and never lasts more than 12 hours.
Limits on sign-in attempts
Sign-in and account requests are limited to 20 a minute from each network address.
Access checked on every research request
Before results are returned, each request is checked against your workspace membership and your role’s permissions. Hiding a link is never the only protection.
Workspaces stay separate
Another workspace cannot see your workspace’s searches, saved work, or document text.

Your research and data

Not used to train AI
We do not use your searches, saved work, or document text to train or fine-tune shared AI.
Question text kept out of AI logs
When Virtus uses AI to answer a question from your workspace, the logs of that request do not keep your question or the answer text.
Public sources, no client files
The library is built from public IRS documents. Virtus does not ask for or accept your clients’ files.
Visits counted without tracking you
We count site visits without cookies and without storing your IP address, and not at all when your browser sends Global Privacy Control.
Demo requests go to our inbox only
A demo request is emailed to our team and is not stored in the product.

Independent certification status

This page describes product controls. It does not claim an independent security certification or audit of Virtus. Certifications held by a service provider are not presented as certifications of this product.

Report a security issue

If you find a security issue, email admin@virtusprofessionalservices.com. Include what you found and how to reproduce it. Please do not access other people’s data while testing.

For how we handle personal information, read the Privacy Notice and the Cookie Policy.

Questions about security? Talk to us.

Walk through Virtus with us, and bring your security questions.