Security & Compliance

Security is our top priority.

You're trusting us with SSNs, EINs, and financial records. Here's what we do to protect them, and where each guarantee actually comes from.

What we protect

Every piece of client data, handled deliberately.

Client identities

Names, SSNs, and EINs are used only to prepare and file your return, and are encrypted at rest and in transit.

Tax documents

W-2s, 1099s, K-1s, and every other upload are encrypted at rest (AES-256) and in transit (TLS).

Payment data

When you pay us, the card is handled by a PCI DSS Level 1 certified payment processor. Acorn9 never stores or touches your card number.

Digital signatures

Form 8879 e-signatures are ESIGN Act & UETA compliant, with a timestamp and IP address captured on every signature.

SOC 2
ISO 27001
PCI DSS
ESIGN / UETA
GLBA
AES-256

SOC 2 and ISO 27001 are held by our infrastructure providers. PCI DSS is held by our payment processor. ESIGN/UETA, GLBA service-provider handling, and AES-256/TLS encryption apply to Acorn9 directly.

The journey

Where your documents go, and where they stop.

How your documents are handled, end to endEncrypted in transitYour documentsFirm-isolated storageAI extraction, no trainingCPA reviewDelivered to youHow your documents are handled, end to endYour documentsEncrypted in transitFirm-isolated storageAI extraction, no trainingCPA reviewDelivered to you

Every firm’s records sit in their own partition; one firm can never see another’s. Documents go to AI for extraction under terms that exclude training, and come back as intermediate work product. A licensed CPA reviews the result before anything is delivered.

Trust Services Criteria

Designed around SOC 2.

Acorn9's own controls are designed around the AICPA SOC 2 Trust Services Criteria. Here is how each criterion shows up in practice.

CC

Security

  • Staff sign in with authenticated accounts. Every client record is scoped to the firm that owns it, and that boundary is enforced in the database, not only in the interface.
  • Client portals open from purpose-bound, unguessable links, with one-time-code verification where the step warrants it.
  • All traffic is encrypted in transit. Stored records and uploaded documents are encrypted at rest.
A

Availability

  • The application runs on managed cloud infrastructure with provider-operated redundancy and backups.
  • Edge-level filtering and DDoS protection sit in front of the application.
PI

Processing integrity

  • AI output is intermediate work product. Extracted fields are cross-checked against the rest of the file, and inconsistencies are flagged before anything moves forward.
  • A licensed CPA reviews every return before it is delivered. The professional signs; the software does not.
C

Confidentiality

  • Client data is used only for the engagement it was collected for.
  • Documents are processed by AI to extract and classify data under paid, enterprise data terms; they are never used to train models.
P

Privacy

  • Acorn9 acts as a service provider under the Gramm-Leach-Bliley Act (GLBA). Nonpublic personal information is collected only as needed to prepare and deliver the return, and is never sold or shared for marketing.
  • Tax documents are retained per IRS guidance.
AI and your data

AI reads the documents. It keeps nothing.

Models extract and classify what is in a document so a CPA does not have to key it in. That is the whole job. Here is what happens to your data along the way.

What happens to a document the AI reads

Never used for training

Your documents, the questions we ask about them, and the answers are not used to train or improve any model. We only use model providers under paid, enterprise terms that say so in writing.

Not retained by the model

A document is sent for one task and comes back as extracted fields. The model provider keeps nothing beyond its short abuse-monitoring window, and nothing is kept to build a profile of you.

Minimum necessary

Each request carries only what the task needs, over an encrypted connection: a single form for extraction, the return's documents for a cross-check, and nothing unrelated to your engagement.

No one at the provider reads it

Under normal operation no human at a model provider sees your documents. Providers reserve review only for abuse monitoring under their own published policy.

A CPA makes every decision

Model output is intermediate work product. Extracted values are cross-checked against the rest of the file, and a licensed CPA reviews the return before it is delivered.

Every provider is vetted

We review a provider's data terms, retention behaviour, and security attestations before any document is routed to it, and we share the current list with clients on request.

Infrastructure

Built on audited cloud providers.

Acorn9 doesn't claim certifications it hasn't earned. The cloud providers we build on each hold SOC 2 Type II and ISO 27001 attestations. Their reports cover their platforms, not Acorn9's application; that part is our responsibility. We share provider details with clients on request.

The layers your data rests on
Built on
Security questions

Ask us anything.

How a workflow handles your data, where AI is used, what a vendor can see — ask in plain language and we answer the same way.