Security & Trust Center
Tax practices handle some of the most sensitive information their clients own. TPP is designed with security, access control, privacy, and accountability throughout the client and staff experience.
Security Architecture
Client
A firm's staff member or their client, using the web dashboard, the client portal, or the mobile app.
Data Protection
Every connection to TPP — staff dashboard, client portal, and mobile app — is made over HTTPS.
Encrypted, access-controlled storage for uploaded documents is part of the infrastructure design and is being built out ahead of general production availability.
A firm can export its own Customer Data and Client Data at any time, including during a restricted trial-expired state — see Terms & Conditions, Section 33.
Routine backups of firm and client data are part of TPP's operational practices — see Terms & Conditions, Section 32.
Authentication
Both the staff dashboard and the client portal require an authenticated session before any tax data is shown.
Firm staff currently sign in with a password. Enforcing an additional verification factor for staff accounts is planned.
A dedicated second authentication factor for client portal logins, separate from staff authentication.
The TPP mobile app supports device biometric login. Your device's operating system handles the biometric check — TPP never receives or stores biometric data.
The enrollment flow for six-digit verification codes is built into the mobile app, but no authenticator or SMS provider is connected yet — it is not usable to protect a real account today.
Passwordless sign-in using device passkeys is on the roadmap.
Access Control
Owner
Full access to every client, return, and firm setting, including billing and staff management.
All permissions
| Area | Owner | Admin | Preparer | Reviewer | Billing | Read Only | Client |
|---|---|---|---|---|---|---|---|
| Client Records | Full | Full | Assigned Only | Assigned Only | None | View Only | Own Only |
| Documents | Full | Full | Assigned Only | View Only | None | View Only | Own Only |
| Tasks | Full | Full | Assigned Only | Approve Only | None | View Only | Own Only |
| Firm Settings | Full | Limited | None | None | None | None | None |
| Billing | Full | Limited | None | None | Full | None | Pay Only |
| Calendar | Full | Full | Assigned Only | View Only | None | View Only | Own Only |
| Communications | Full | Full | Assigned Only | View Only | None | None | Own Only |
| Tax Returns | Full | Full | Assigned Only | Approve Only | None | View Only | Own Only |
| Reports | Full | Full | None | None | Limited | View Only | None |
Access levels are summarized from each role's description in Firm Management → Staff & Roles. Hover a badge with a note for detail.
Document Security
Client
A client prepares to send a document from their portal or the mobile app.
Client Portal Security
Client Login
A client signs in to their portal with their own credentials — never a shared or firm-wide login.
Communication Security
Messages sent through the TPP client portal live inside an authenticated session and stay attached to the client's record. Ordinary email sent through a connected Gmail or Outlook account is regular email — useful for firm communication, but it is not the same protection level as in-portal messaging, and TPP does not claim otherwise.
Clients and staff can message each other inside the authenticated portal, with the conversation history tied to the client record.
Firms can send and log ordinary email from inside TPP once they connect Gmail, Google Workspace, or Outlook — this is regular email, not encrypted portal messaging (see the Communication Security section for the distinction).
Text-message appointment and document reminders, sent through a carrier-connected provider.
Activity & Audit History
| Who | Action | Object | When |
|---|---|---|---|
| Priya Shah | Viewed | Sofia Nguyen — 2025 W-2 | Aug 30, 2026 |
Privacy
TPP handles the information a firm and its clients need to exchange to prepare a return: account and firm details, client documents, in-portal communications, and security-relevant activity logs. This information exists to run the engagement — not for resale, and not for advertising. Firms may choose to connect third-party services (see below); TPP does not otherwise share client tax data with third parties.
Incident Response
Identify the affected scope and limit further exposure as quickly as possible.
Determine what happened, fix the underlying cause, and confirm it's closed.
Notify the affected firm's administrator without undue delay and restore normal operation.
Per our Terms & Conditions (Section 44), if we become aware of a security incident affecting a firm's data, we notify that firm's designated administrator without undue delay and in accordance with applicable law. We don't publish a specific incident-response SLA beyond that commitment today.
Business Continuity
Routine backups and data export are operational practices described in our Terms & Conditions (Sections 32–33) — a firm is never locked out of its own records, including during a restricted trial-expired state. Broader redundancy and disaster-recovery infrastructure beyond routine backups is an architecture objective as TPP scales, not yet a published guarantee.
Third-Party Services
TPP itself doesn't require any third-party connection to function. Firms may optionally connect real third-party services through the Integrations Hub — most use their own OAuth sign-in, so TPP never sees or stores your password for that service. A few examples, out of 43 cataloged integrations:
QuickBooks Online
Accounting
Google Calendar
Scheduling
Microsoft Outlook Calendar
Scheduling
Stripe
Payments
Xero
Accounting
Microsoft 365
Scheduling
DocuSign
E-Signature
QuickBooks Payroll
Payroll
Security for Tax Practices
A tax engagement moves through some of the most sensitive documents a client has. TPP's document categories, visibility controls, and activity history are built with that in mind — shown here as category labels only, never real client data.
Client vs. Staff Security
Client can
Staff can
Staff access is further narrowed by role — see the Permissions section above for the full breakdown.
See It In Practice
Client signs in
The client authenticates with their own portal credentials.
Security FAQ
Uploads and downloads happen over HTTPS, through an authenticated session, scoped to the owning firm and client. Staff must have the right role and document-visibility access to open a file, and that access is recorded in the document's activity history.
The TPP mobile app supports biometric login (Face ID / fingerprint) today. Authenticator-app or SMS verification codes have a complete enrollment UI but no connected provider yet (in development). Client two-factor authentication is coming soon, and enforced staff MFA is planned.
Every staff member is assigned one of six roles — Owner, Admin, Preparer, Reviewer, Billing, or Read Only — each with a defined access level, set by the firm's Owner or Admin in Firm Management → Staff & Roles.
Yes. A client portal login is scoped to exactly one client record — its documents, messages, tasks, and appointments — and cannot see any other client's information.
Yes, per-record: documents, tasks, appointments, integration connections, branding changes, and trial events each keep a real activity log of who did what and when. A single, unified, IP-logged audit feed across every action is in development.
If we become aware of a security incident affecting a firm's data, our Terms & Conditions (Section 44) commit to notifying that firm's designated administrator without undue delay and in accordance with applicable law. We don't publish a specific incident-response SLA beyond that commitment today.
Messages sent through the client portal live inside an authenticated session and stay tied to the client's record. Ordinary email sent through a connected Gmail or Outlook account is regular email — useful for firm communication, but not the same protection level as in-portal messaging. We're explicit about that difference rather than blurring it.
In TPP's application database, scoped per firm. TPP does not sell or share client tax data with third parties except the integrations a firm explicitly connects (see the Integrations page for exactly which ones, and what each syncs).
See Terms & Conditions, Sections 32–36, for how backups, data export, and post-termination retention work. We do not delete a firm's Client Data simply because a trial expires.
Firms may choose to connect real third-party services — accounting software, e-signature, calendar, payment processors — through the Integrations Hub. Each one is OAuth-based where the vendor supports it, so TPP never sees your password for that service. See the Integrations Center for the full, honestly-labeled list.
HTTPS everywhere, authenticated staff and client sessions, per-firm data isolation, six-role staff permissions, client-scoped portal access, document visibility flags, per-record activity history, in-portal secure messaging, and mobile biometric login.
Client two-factor authentication and SMS reminders are marked Coming Soon. A connected authenticator/SMS provider for verification codes, a unified IP-logged audit trail, encrypted-at-rest document storage, staff MFA enforcement, and passkey sign-in are in development or planned — see the status label on each page.
Security Contact
Contact the TPP team — we route security inquiries to the right people.
Contact the TPP team30-day free trial. Full access to every feature during your trial, subject to the applicable trial terms.