Each firm works in its own workspace
No other firm can see your client data, workflows, or firm-specific settings. Client data is never pooled across customers and is never used to train shared models.
You sign the return with your license. Here is exactly how the data behind it is protected — what is live today, and what is still in examination.
Nothing is transmitted without reviewer approval · 8879 first, always
Every control on this page supports one of them.
No other firm can see your client data, workflows, or firm-specific settings. Client data is never pooled across customers and is never used to train shared models.
All data is encrypted at rest and TLS-encrypted in transit. Keys are managed separately from the application and rotate automatically. Point-in-time backups protect against data loss.
Nothing is transmitted to the IRS, delivered to a client, or posted to a ledger without your reviewer's approval and a signed Form 8879. Every number links back to its source document, so the reviewer sees the page behind it.
Talk to a founder to review each one with your team.
Each firm operates in a logically isolated workspace, and access is assigned according to responsibility.
Files, extracted tax data, and workpapers are encrypted at rest across the platform, with keys managed outside the application.
Every connection between your firm, your clients' portal, and TaxScout is encrypted in transit.
Owners, partners, staff, and reviewers get scoped permissions; multi-factor authentication can be enforced firm-wide. SMS-only MFA is not offered for privileged roles.
Material actions involving documents, client data, review, and financial information are recorded with the actor and timestamp. Logs are append-only and exportable for compliance reviews.
SSNs and the most sensitive identifiers are held under additional protection and masked in the interface by default.
TaxScout maintains encrypted backups that support recovery and continuity. Documents are versioned, so an overwrite or deletion is recoverable.
Every figure on a return links back to the document, page, and field it came from — the review trail is part of the data model.
Each one carries its own status — nothing is blended into a badge wall.
Controls are designed and mapped to the AICPA Trust Services Criteria — Security, Availability, Confidentiality. The independent Type II examination is in progress; the report will be shared under NDA once it is complete.
The security program follows Safeguarding Taxpayer Data: written security plan, access controls, encryption, retention, and breach response specific to tax-preparer obligations.
Aligned with 16 CFR Part 314: a designated qualified individual, written risk assessments, encryption of customer information, MFA, and incident-response procedures.
Intake, extraction, preparation, and filing stay onshore, so the offshore-disclosure consent conversation never has to happen with your clients.
Detection through customer notification, with the clock stated.
Production is monitored around the clock. Anomaly rules trigger on unusual access patterns, mass document downloads, privilege escalations, and outbound transfers above baseline.
An on-call engineer is paged within five minutes of a critical alert. Playbooks cover compromised credentials, data exposure, and code injection.
Material incidents affecting customer data are communicated within 24 hours of confirmation — scope, affected data, actions taken, and what you need to do.
Every incident gets a blameless post-mortem within five business days; remediation closes within 30 days.
FAQ
No. Each firm works in its own workspace. No other TaxScout customer can see your client data, workflows, or firm-specific settings, and client data is never shared across customers or used to train shared models.