Security & Data Handling
How TaxAutomate handles tax documents, protects data, and maintains security.
Document Intake
Accepted File Types
- PDF (preferred)
- JPEG, PNG (image files)
- TIFF (multi-page supported)
Upload Process
- HTTPS (TLS 1.2 or higher)
- Max file size: 25 MB
- File type validation
- Password-protected PDFs must be unlocked
Pre-Processing Validation
- File integrity check
- Malware scanning
- Format validation
Temporary Storage
Documents are stored temporarily during processing and for a limited period afterward.
| Data Type | Retention |
|---|---|
| Original documents | 30 days after processing |
| Extracted data | Until client deleted |
| Return data | Entered directly into your tax software; no import files generated |
Storage Security: All data encrypted with AES-256 at rest, stored in US data centers with firm-level isolation.
Access Controls
User Authentication
- Enterprise-grade identity provider
- Multi-factor authentication available
- Session timeout after inactivity
Authorization
- Users can only access their own firm's data
- Role-based access: Owner, Admin, Preparer, Viewer
- All data access is logged
Internal Access
- Staff access limited to support and maintenance
- Access requires explicit authorization and is logged
- Customer documents are not used for training
Deletion Policy
Automatic Deletion
- Original uploaded documents: 30 days after processing
- Temporary processing files: Within 24 hours
User-Initiated Deletion
- Delete individual clients and associated documents
- Firm owners can request complete data deletion
- Deletion requests processed within 30 days
Account Closure
When an account is closed, all associated data is scheduled for deletion within 30 days. Audit logs may be retained for compliance purposes.
Data Processing
OCR Processing
- Processed using Azure Document Intelligence
- Processing occurs in Microsoft Azure's US data centers
- Microsoft does not retain document content
Sensitive Data Handling
- SSNs and EINs are encrypted separately
- SSNs displayed as last 4 digits only in UI
- Full SSNs used only when entering the return into your tax software
Compliance
TaxAutomate is designed to support tax professionals in maintaining their compliance obligations.
Security Practices
- Data encrypted in transit and at rest
- Regular security assessments
- Audit logging of data access
- Employee security training
IRS Safeguards
Tax professionals using TaxAutomate should ensure their use complies with IRS Publication 4557 (Safeguarding Taxpayer Data) and their own written information security plan.
Incident Response
In the event of a security incident affecting customer data, affected customers will be notified within 72 hours with description of affected data and recommended actions.
Security Questions
For security-related questions or to report a concern, contact [email protected].