Security
How we protect your research and account.
What protects your account and your research today, stated plainly. We list only what Virtus actually does.
Hosting and connections
Hosted on Cloudflare
Virtus runs on Cloudflare’s network at virtusprofessionalservices.com.
Encrypted connections
Pages are served over HTTPS, and your browser is told to use only HTTPS for this site for the next year.
No embedding, no outside scripts
Other websites cannot show Virtus pages inside their own. Pages load scripts, styles, fonts, and images only from Virtus itself.
Changes only from our own pages
Requests that change anything are accepted only when they come from Virtus’s own pages, so another site cannot act for you.
Accounts and workspace access
A protected sign-in cookie
Your sign-in is kept in one signed cookie that page scripts cannot read (HttpOnly), that travels only over HTTPS (Secure), and that is not sent with requests from other sites (SameSite=Lax). It ends after 30 minutes without activity and never lasts more than 12 hours.
Limits on sign-in attempts
Sign-in and account requests are limited to 20 a minute from each network address.
Access checked on every research request
Before results are returned, each request is checked against your workspace membership and your role’s permissions. Hiding a link is never the only protection.
Workspaces stay separate
Another workspace cannot see your workspace’s searches, saved work, or document text.
Your research and data
Not used to train AI
We do not use your searches, saved work, or document text to train or fine-tune shared AI.
Question text kept out of AI logs
When Virtus uses AI to answer a question from your workspace, the logs of that request do not keep your question or the answer text.
Public sources, no client files
The library is built from public IRS documents. Virtus does not ask for or accept your clients’ files.
Visits counted without tracking you
We count site visits without cookies and without storing your IP address, and not at all when your browser sends Global Privacy Control.
Demo requests go to our inbox only
A demo request is emailed to our team and is not stored in the product.
Report a security issue
If you find a security issue, email admin@virtusprofessionalservices.com. Include what you found and how to reproduce it. Please do not access other people’s data while testing.
For how we handle personal information, read the Privacy Notice and the Cookie Policy.
Questions about security? Talk to us.
Walk through Virtus with us, and bring your security questions.