FOR TAX PROFESSIONALS|FIND A TAX PROFESSIONAL
SECURITY & COMPLIANCE — FOR THE FIRM THAT SIGNS THE RETURN

Your clients’ data never leaves the country.

You sign the return with your license. Here is exactly how the data behind it is protected — what is live today, and what is still in examination.

Nothing is transmitted without reviewer approval · 8879 first, always

SOC 2 Type IIExamination in progress
Enterprise controlsEncryption · RBAC · MFA · audit logs
IRS Pub 4557 · GLBASafeguards Rule mapped
Three safeguards

Three safeguards, across every workflow.

Every control on this page supports one of them.

Privacy

Each firm works in its own workspace

No other firm can see your client data, workflows, or firm-specific settings. Client data is never pooled across customers and is never used to train shared models.

Encryption

Encryption across the platform

All data is encrypted at rest and TLS-encrypted in transit. Keys are managed separately from the application and rotate automatically. Point-in-time backups protect against data loss.

Review

Your reviewers approve everything

Nothing is transmitted to the IRS, delivered to a client, or posted to a ledger without your reviewer's approval and a signed Form 8879. Every number links back to its source document, so the reviewer sees the page behind it.

Enterprise security controls

The controls behind the safeguards.

Talk to a founder to review each one with your team.

One firm, one workspace

Each firm operates in a logically isolated workspace, and access is assigned according to responsibility.

Encrypted at rest

Files, extracted tax data, and workpapers are encrypted at rest across the platform, with keys managed outside the application.

TLS in transit

Every connection between your firm, your clients' portal, and TaxScout is encrypted in transit.

Role-based access & MFA

Owners, partners, staff, and reviewers get scoped permissions; multi-factor authentication can be enforced firm-wide. SMS-only MFA is not offered for privileged roles.

Audit logs

Material actions involving documents, client data, review, and financial information are recorded with the actor and timestamp. Logs are append-only and exportable for compliance reviews.

PII protection

SSNs and the most sensitive identifiers are held under additional protection and masked in the interface by default.

Point-in-time backups

TaxScout maintains encrypted backups that support recovery and continuity. Documents are versioned, so an overwrite or deletion is recoverable.

Source-linked outputs

Every figure on a return links back to the document, page, and field it came from — the review trail is part of the data model.

Frameworks

The standards your vendor review asks about.

Each one carries its own status — nothing is blended into a badge wall.

SOC 2 Type II

Controls are designed and mapped to the AICPA Trust Services Criteria — Security, Availability, Confidentiality. The independent Type II examination is in progress; the report will be shared under NDA once it is complete.

IRS Publication 4557

Mapped

The security program follows Safeguarding Taxpayer Data: written security plan, access controls, encryption, retention, and breach response specific to tax-preparer obligations.

GLBA Safeguards Rule

Mapped

Aligned with 16 CFR Part 314: a designated qualified individual, written risk assessments, encryption of customer information, MFA, and incident-response procedures.

IRC §7216

By design

Intake, extraction, preparation, and filing stay onshore, so the offshore-disclosure consent conversation never has to happen with your clients.

Incident response

What actually happens when something goes wrong.

Detection through customer notification, with the clock stated.

01

Detection

Production is monitored around the clock. Anomaly rules trigger on unusual access patterns, mass document downloads, privilege escalations, and outbound transfers above baseline.

02

Containment

An on-call engineer is paged within five minutes of a critical alert. Playbooks cover compromised credentials, data exposure, and code injection.

03

Notification

Material incidents affecting customer data are communicated within 24 hours of confirmation — scope, affected data, actions taken, and what you need to do.

04

Remediation

Every incident gets a blameless post-mortem within five business days; remediation closes within 30 days.

Shared responsibility

The line between what we own and what your firm owns.

What TaxScout protects
  • Infrastructure security — network, servers, database
  • Application security — authentication, encryption, access controls
  • Compliance alignment — SOC 2 criteria, GLBA, IRS Pub 4557
  • Backup, recovery, and continuity of production
  • Monitoring, detection, and incident response
What your firm owns
  • Strong passwords and MFA enrollment for every team member
  • Access scope — no broader roles than the work needs
  • Prompt off-boarding when staff leave
  • Local device security — disk encryption, screen lock, updates
  • Phishing awareness — TaxScout never asks for your password by email
Documentation

For vendor reviews and peer-review requirements.

FAQ

Security questions, answered

No. Each firm works in its own workspace. No other TaxScout customer can see your client data, workflows, or firm-specific settings, and client data is never shared across customers or used to train shared models.

30 minutes · a founder, not sales

Bring your security questionnaire. Leave with it answered.