Sensitive client work deserves clear access, review, approval, and accountability.
SOC 2–ready security and professional control

AI moves the work forward. Your tax professional stays in control.

Tax Automate is designed to keep client work inside controlled workflows with appropriate access, clear exceptions, professional review, approval, sign-off, and delivery safeguards.

SOC 2–ready, not yet SOC 2 certified. Security documentation and readiness details can be reviewed with your firm during evaluation.
2025 Individual Return · Control statusSOC 2–READY FOUNDATION
ID
Role-based accessAssigned preparer and reviewer
VERIFIED
AI
Automation outputExceptions surfaced for review
READY
REV
Professional reviewSenior reviewer approval required
PENDING
OUT
Client deliveryLocked until final sign-off
CONTROLLED
Control throughout the work

Protect access, preserve accountability, and keep judgment with professionals.

Security is not only about where data sits. It also depends on who can access it, what they can do, and which reviews must happen before work moves forward.

01 · ACCESS

Role-based access

Align access with office, team, client, role, and work responsibility.

02 · REVIEW

Professional oversight

Require qualified professionals to validate facts, outputs, and client-facing work.

03 · HISTORY

Accountable workflows

Maintain assignments, status changes, approvals, and delivery history.

04 · EXCEPTIONS

Clear attention points

Surface missing items, conflicts, and areas needing human judgment.

A layered operating model

Security and control across the client, workforce, workflow, and platform.

CLIENT DATA

Keep context connected and appropriately visible.

Organize client records, entities, documents, communications, questionnaires, and work within authorized workflows.

  • Client and entity-level organization
  • Controlled document and communication context
  • Supported integration boundaries
WORKFORCE ACCESS

Give each person the access required for their role.

Support firm, office, team, and assignment-based operating structures without giving everyone the same reach.

  • Role and responsibility alignment
  • Office and team ownership
  • Professional review authority
WORKFLOW CONTROL

Make review and approval part of the process.

Keep automation outputs, exceptions, tasks, handoffs, sign-off, and delivery within a defined sequence.

  • Review and approval gates
  • Missing-item and exception handling
  • Controlled client and agency delivery
PLATFORM SAFEGUARDS

Review the technical deployment with your firm.

Implementation-specific hosting, access, integration, retention, and security documentation should be evaluated during technical review.

  • Deployment and data-flow review
  • Integration and access assessment
  • Security documentation during evaluation
Human review by design

No critical deliverable leaves the workflow without professional approval.

Automation can organize, extract, summarize, draft, and surface exceptions. Your authorized professional evaluates the facts, applies judgment, approves the final work, and controls delivery to the client or agency.

Tax return review and approval before finalization
Notice-response validation before agency or client delivery
Planning assumptions and recommendations reviewed by professionals
Client communications and AI-assisted drafts subject to firm controls
Professional approval workflowDELIVERY LOCKED
1Automation organizes the work and surfaces exceptions.COMPLETE
2Assigned professional reviews facts, assumptions, and outputs.IN REVIEW
3Authorized reviewer approves and signs off.REQUIRED
4Work becomes available for controlled delivery.LOCKED
SOC 2 readiness and responsible evaluation

Building the control foundation for a future SOC 2 examination.

Tax Automate is SOC 2–ready: the platform and operating processes are being prepared around the controls, documentation, and evidence expected for a future SOC 2 examination. Tax Automate is not yet SOC 2 certified or attested.

Control readiness

Access, workflow, change, operational, and security controls are being organized and documented as part of the readiness process.

Evidence readiness

Policies, responsibilities, system information, and operating evidence must be maintained so an independent auditor can evaluate the controls.

Clear current status

SOC 2–ready describes preparation for an examination. It does not mean that an audit has been completed or that a SOC 2 report has been issued.

Current status: SOC 2–ready; not yet SOC 2 certified, attested, or compliant. Specific encryption, hosting, retention, backup, incident-response, and regulatory details should be confirmed in current security documentation before production use.
Security FAQs

Questions tax firms ask during security review.

Does Tax Automate use role-based access?

The platform is designed to align access with firm, office, team, client, role, and workflow responsibilities. Specific configuration should be reviewed during implementation.

Does AI automatically finalize or send tax work?

No. Critical returns, notice responses, plans, and client-facing deliverables are intended to remain subject to authorized professional review and approval.

Can we review security documentation?

Available technical and operational documentation can be discussed during the evaluation process based on your deployment and integration scope.

How are integrations evaluated?

Each supported integration should be reviewed for authentication, data flow, permissions, operational ownership, and the information exchanged between systems.

Is Tax Automate SOC 2 compliant?

Not yet. Tax Automate is SOC 2–ready, meaning the control and evidence foundation is being prepared for a future examination. No SOC 2 report has been issued at this time.

Who remains responsible for professional decisions?

Your authorized tax professionals remain responsible for verifying facts, applying judgment, approving work, and controlling client or agency delivery.

Bring your security, operational, and professional-control questions.

Tell us which products, workflows, offices, integrations, and data requirements you are evaluating. We’ll prepare the appropriate security and deployment discussion.

Review access and workflow controlsDiscuss deployment and integrationsConfirm professional approval responsibilities