You're trusting us with SSNs, EINs, and financial records. Here's what we do to protect them, and where each guarantee actually comes from.
Names, SSNs, and EINs are used only to prepare and file your return, and are encrypted at rest and in transit.
W-2s, 1099s, K-1s, and every other upload are encrypted at rest (AES-256) and in transit (TLS).
When you pay us, the card is handled by a PCI DSS Level 1 certified payment processor. Acorn9 never stores or touches your card number.
Form 8879 e-signatures are ESIGN Act & UETA compliant, with a timestamp and IP address captured on every signature.
SOC 2 and ISO 27001 are held by our infrastructure providers. PCI DSS is held by our payment processor. ESIGN/UETA, GLBA service-provider handling, and AES-256/TLS encryption apply to Acorn9 directly.
Every firm’s records sit in their own partition; one firm can never see another’s. Documents go to AI for extraction under terms that exclude training, and come back as intermediate work product. A licensed CPA reviews the result before anything is delivered.
Acorn9's own controls are designed around the AICPA SOC 2 Trust Services Criteria. Here is how each criterion shows up in practice.
Models extract and classify what is in a document so a CPA does not have to key it in. That is the whole job. Here is what happens to your data along the way.
Your documents, the questions we ask about them, and the answers are not used to train or improve any model. We only use model providers under paid, enterprise terms that say so in writing.
A document is sent for one task and comes back as extracted fields. The model provider keeps nothing beyond its short abuse-monitoring window, and nothing is kept to build a profile of you.
Each request carries only what the task needs, over an encrypted connection: a single form for extraction, the return's documents for a cross-check, and nothing unrelated to your engagement.
Under normal operation no human at a model provider sees your documents. Providers reserve review only for abuse monitoring under their own published policy.
Model output is intermediate work product. Extracted values are cross-checked against the rest of the file, and a licensed CPA reviews the return before it is delivered.
We review a provider's data terms, retention behaviour, and security attestations before any document is routed to it, and we share the current list with clients on request.
Acorn9 doesn't claim certifications it hasn't earned. The cloud providers we build on each hold SOC 2 Type II and ISO 27001 attestations. Their reports cover their platforms, not Acorn9's application; that part is our responsibility. We share provider details with clients on request.
How a workflow handles your data, where AI is used, what a vendor can see — ask in plain language and we answer the same way.