SECURITY

Identity, authorization, data scope, and evidence are separate controls.

This page describes controls implemented by this corporate gateway. It does not certify every linked application or external provider.

Managed authentication

Sign-in is provider managed. The Ross sign-in page does not maintain a local password field.

Backend authorization

Private account and owner routes validate the authenticated provider session on the backend. Owner routes also enforce the configured owner email allowlist.

Scoped storage

Account profiles, preferences, and support requests use application storage scoped by authenticated identity where applicable.

Secrets boundary

External credentials and secrets are not embedded in static source. External systems require separately authorized credentials and connections.

Connection truthfulness

Registered deployment inventory is labeled separately from live connectivity, OAuth grants, agency access, and service health.

Shared-device control

Users can sign out of this application from Account Security. That action does not claim to terminate unrelated provider or application sessions.

For account-specific controls, open Account Security. For urgent security issues, use the Security support category after signing in.
Ross Tax Pro Software Co.

Tax Solutions. Systems. Career Development.

Operational and authority claims remain subject to source verification and production controls. Application inventory is not the same as live external-system connectivity.