HomeDocumentation

Documentation

Everything you need to get started with TaxAutomate

Security & Data Handling

How TaxAutomate handles tax documents, protects data, and maintains security.

Document Intake

Accepted File Types

  • PDF (preferred)
  • JPEG, PNG (image files)
  • TIFF (multi-page supported)

Upload Process

  • HTTPS (TLS 1.2 or higher)
  • Max file size: 25 MB
  • File type validation
  • Password-protected PDFs must be unlocked

Pre-Processing Validation

  • File integrity check
  • Malware scanning
  • Format validation

Temporary Storage

Documents are stored temporarily during processing and for a limited period afterward.

Data TypeRetention
Original documents30 days after processing
Extracted dataUntil client deleted
Return dataEntered directly into your tax software; no import files generated

Storage Security: All data encrypted with AES-256 at rest, stored in US data centers with firm-level isolation.

Access Controls

User Authentication

  • Enterprise-grade identity provider
  • Multi-factor authentication available
  • Session timeout after inactivity

Authorization

  • Users can only access their own firm's data
  • Role-based access: Owner, Admin, Preparer, Viewer
  • All data access is logged

Internal Access

  • Staff access limited to support and maintenance
  • Access requires explicit authorization and is logged
  • Customer documents are not used for training

Deletion Policy

Automatic Deletion

  • Original uploaded documents: 30 days after processing
  • Temporary processing files: Within 24 hours

User-Initiated Deletion

  • Delete individual clients and associated documents
  • Firm owners can request complete data deletion
  • Deletion requests processed within 30 days

Account Closure

When an account is closed, all associated data is scheduled for deletion within 30 days. Audit logs may be retained for compliance purposes.

Data Processing

OCR Processing

  • Processed using Azure Document Intelligence
  • Processing occurs in Microsoft Azure's US data centers
  • Microsoft does not retain document content

Sensitive Data Handling

  • SSNs and EINs are encrypted separately
  • SSNs displayed as last 4 digits only in UI
  • Full SSNs used only when entering the return into your tax software

Compliance

TaxAutomate is designed to support tax professionals in maintaining their compliance obligations.

Security Practices

  • Data encrypted in transit and at rest
  • Regular security assessments
  • Audit logging of data access
  • Employee security training

IRS Safeguards

Tax professionals using TaxAutomate should ensure their use complies with IRS Publication 4557 (Safeguarding Taxpayer Data) and their own written information security plan.

Incident Response

In the event of a security incident affecting customer data, affected customers will be notified within 72 hours with description of affected data and recommended actions.

Security Questions

For security-related questions or to report a concern, contact [email protected].