Compliance glossary
Definition

Tax Software Security

The combined responsibilities of the tax software vendor and the firm for protecting taxpayer data inside tax preparation software.

What it means.

Tax software security covers both the vendor's controls (encryption, MFA, secure infrastructure, vulnerability management) and the firm's configuration (user provisioning, role permissions, access reviews, audit logging). The IRS holds the firm responsible for safeguarding taxpayer data regardless of which software is used. CPA firms should evaluate tax software vendors for SOC 2 reports, encryption standards, MFA support, breach notification commitments, and data export and portability.

Why it matters for CPA firms.

Major tax software vendors have been breached. When they are, every firm that uses them faces a notifiable incident. The firm cannot delegate its security obligations to the vendor; the firm must verify, document, and re-verify each year. Vendor due diligence is part of the FTC Safeguards Rule service provider oversight requirement. Pick vendors that can produce a SOC 2 or equivalent on request.

Relevant regulations.

  • 16 CFR 314.4(f)
  • IRS Publication 4557
  • IRS Publication 5708

How Kompflow helps.

The Vendor Assessment Module module handles this for your firm, personalized to your software, team size, and state requirements.

See plans and pricing

Related terms.

Ready when you are

Pick where to start.

Buy the WISP yourself if you need the document.
Talk to us if you want the platform.

30-day money-back on Kompflow WISPCancel anytimeNo setup fees on any tier

We use cookies to measure site performance and improve your experience. No data is sold to third parties. Privacy Policy