Security & Trust Center

Security is part of the product.

Tax practices handle some of the most sensitive information their clients own. TPP is designed with security, access control, privacy, and accountability throughout the client and staff experience.

13 Implemented·3 In Development·2 Coming Soon·2 Planned

Security Architecture

How a request moves through TPP.

Security Architecture — Conceptual

Client

A firm's staff member or their client, using the web dashboard, the client portal, or the mobile app.

Data Protection

Encryption, storage, backups, and retention.

HTTPS for all connections

Every connection to TPP — staff dashboard, client portal, and mobile app — is made over HTTPS.

Implemented

Encryption at rest for stored documents

Encrypted, access-controlled storage for uploaded documents is part of the infrastructure design and is being built out ahead of general production availability.

In Development

Firm data export

A firm can export its own Customer Data and Client Data at any time, including during a restricted trial-expired state — see Terms & Conditions, Section 33.

Implemented

Routine data backups

Routine backups of firm and client data are part of TPP's operational practices — see Terms & Conditions, Section 32.

Implemented

See the full data protection walkthrough →

Authentication

Password security, MFA, sessions, and recovery.

Authenticated staff & client sessions

Both the staff dashboard and the client portal require an authenticated session before any tax data is shown.

Implemented

Staff multi-factor authentication

Firm staff currently sign in with a password. Enforcing an additional verification factor for staff accounts is planned.

Planned

Client two-factor authentication

A dedicated second authentication factor for client portal logins, separate from staff authentication.

Coming Soon

Mobile biometric login (Face ID / fingerprint)

The TPP mobile app supports device biometric login. Your device's operating system handles the biometric check — TPP never receives or stores biometric data.

Implemented

Authenticator app / SMS verification codes

The enrollment flow for six-digit verification codes is built into the mobile app, but no authenticator or SMS provider is connected yet — it is not usable to protect a real account today.

In Development

Passkey sign-in

Passwordless sign-in using device passkeys is on the roadmap.

Planned

Try the interactive sign-in demo →

Access Control

Give the right people the right access.

Owner

Full access to every client, return, and firm setting, including billing and staff management.

All permissions

AreaOwnerAdminPreparerReviewerBillingRead OnlyClient
Client RecordsFullFullAssigned OnlyAssigned OnlyNoneView OnlyOwn Only
DocumentsFullFullAssigned OnlyView OnlyNoneView OnlyOwn Only
TasksFullFullAssigned OnlyApprove OnlyNoneView OnlyOwn Only
Firm SettingsFullLimitedNoneNoneNoneNoneNone
BillingFullLimitedNoneNoneFullNonePay Only
CalendarFullFullAssigned OnlyView OnlyNoneView OnlyOwn Only
CommunicationsFullFullAssigned OnlyView OnlyNoneNoneOwn Only
Tax ReturnsFullFullAssigned OnlyApprove OnlyNoneView OnlyOwn Only
ReportsFullFullNoneNoneLimitedView OnlyNone

Access levels are summarized from each role's description in Firm Management → Staff & Roles. Hover a badge with a note for detail.

Read more about TPP's role model →

Document Security

How a document moves from client to firm.

Document Security Flow — Conceptual

Client

A client prepares to send a document from their portal or the mobile app.

Client Portal Security

How a client accesses their own information.

Client Portal — Conceptual

Client Login

A client signs in to their portal with their own credentials — never a shared or firm-wide login.

Communication Security

In-portal messaging vs. ordinary email and SMS.

Messages sent through the TPP client portal live inside an authenticated session and stay attached to the client's record. Ordinary email sent through a connected Gmail or Outlook account is regular email — useful for firm communication, but it is not the same protection level as in-portal messaging, and TPP does not claim otherwise.

In-portal secure messaging

Clients and staff can message each other inside the authenticated portal, with the conversation history tied to the client record.

Implemented

Connected firm email (Gmail / Outlook)

Firms can send and log ordinary email from inside TPP once they connect Gmail, Google Workspace, or Outlook — this is regular email, not encrypted portal messaging (see the Communication Security section for the distinction).

Implemented

SMS reminders

Text-message appointment and document reminders, sent through a carrier-connected provider.

Coming Soon

Activity & Audit History

Who did what, and when.

Sample Activity — Demo Data
WhoActionObjectWhen
Priya ShahViewedSofia Nguyen — 2025 W-2Aug 30, 2026

See the full activity history walkthrough →

Privacy

What information TPP handles, and why.

TPP handles the information a firm and its clients need to exchange to prepare a return: account and firm details, client documents, in-portal communications, and security-relevant activity logs. This information exists to run the engagement — not for resale, and not for advertising. Firms may choose to connect third-party services (see below); TPP does not otherwise share client tax data with third parties.

Incident Response

How TPP approaches a security incident.

Detection & Containment

Identify the affected scope and limit further exposure as quickly as possible.

Investigation & Remediation

Determine what happened, fix the underlying cause, and confirm it's closed.

Communication & Recovery

Notify the affected firm's administrator without undue delay and restore normal operation.

Per our Terms & Conditions (Section 44), if we become aware of a security incident affecting a firm's data, we notify that firm's designated administrator without undue delay and in accordance with applicable law. We don't publish a specific incident-response SLA beyond that commitment today.

Business Continuity

Backups, availability, and recovery.

Routine backups and data export are operational practices described in our Terms & Conditions (Sections 32–33) — a firm is never locked out of its own records, including during a restricted trial-expired state. Broader redundancy and disaster-recovery infrastructure beyond routine backups is an architecture objective as TPP scales, not yet a published guarantee.

Third-Party Services

Services a firm may choose to connect.

TPP itself doesn't require any third-party connection to function. Firms may optionally connect real third-party services through the Integrations Hub — most use their own OAuth sign-in, so TPP never sees or stores your password for that service. A few examples, out of 43 cataloged integrations:

QuickBooks Online

Accounting

Google Calendar

Scheduling

Microsoft Outlook Calendar

Scheduling

Stripe

Payments

Xero

Accounting

Microsoft 365

Scheduling

DocuSign

E-Signature

QuickBooks Payroll

Payroll

See the full Integration Center →

Security for Tax Practices

Built around the realities of tax practice.

A tax engagement moves through some of the most sensitive documents a client has. TPP's document categories, visibility controls, and activity history are built with that in mind — shown here as category labels only, never real client data.

W-2s1099sK-1sBank StatementsInvestment DocumentsIdentity DocumentsPrior Year Tax ReturnsTax NoticesEngagement Letters

Client vs. Staff Security

Two different views into one firm.

Client can

  • Access their own portal
  • Upload documents
  • View their own client-visible documents
  • Message the firm
  • Complete tasks assigned to them
  • Sign documents
  • View and confirm their own appointments
  • View and pay their own invoices

Staff can

  • Manage clients assigned to them (or all clients, for Owner/Admin)
  • Request documents from clients
  • Review and mark documents reviewed
  • Manage tasks and workflow templates
  • Communicate with clients in-portal and by connected email
  • Schedule and manage appointments
  • Access information according to their assigned role's permissions

Staff access is further narrowed by role — see the Permissions section above for the full breakdown.

See It In Practice

Explore how TPP protects a client engagement.

Client Engagement Walkthrough — Conceptual

Client signs in

The client authenticates with their own portal credentials.

Security FAQ

Common questions, answered plainly.

How does TPP protect client documents?+

Uploads and downloads happen over HTTPS, through an authenticated session, scoped to the owning firm and client. Staff must have the right role and document-visibility access to open a file, and that access is recorded in the document's activity history.

Does TPP support multi-factor authentication?+

The TPP mobile app supports biometric login (Face ID / fingerprint) today. Authenticator-app or SMS verification codes have a complete enrollment UI but no connected provider yet (in development). Client two-factor authentication is coming soon, and enforced staff MFA is planned.

How are permissions managed?+

Every staff member is assigned one of six roles — Owner, Admin, Preparer, Reviewer, Billing, or Read Only — each with a defined access level, set by the firm's Owner or Admin in Firm Management → Staff & Roles.

Can clients access only their own documents?+

Yes. A client portal login is scoped to exactly one client record — its documents, messages, tasks, and appointments — and cannot see any other client's information.

Does TPP track account activity?+

Yes, per-record: documents, tasks, appointments, integration connections, branding changes, and trial events each keep a real activity log of who did what and when. A single, unified, IP-logged audit feed across every action is in development.

How does TPP handle security incidents?+

If we become aware of a security incident affecting a firm's data, our Terms & Conditions (Section 44) commit to notifying that firm's designated administrator without undue delay and in accordance with applicable law. We don't publish a specific incident-response SLA beyond that commitment today.

How does TPP protect client communications?+

Messages sent through the client portal live inside an authenticated session and stay tied to the client's record. Ordinary email sent through a connected Gmail or Outlook account is regular email — useful for firm communication, but not the same protection level as in-portal messaging. We're explicit about that difference rather than blurring it.

Where is client data stored?+

In TPP's application database, scoped per firm. TPP does not sell or share client tax data with third parties except the integrations a firm explicitly connects (see the Integrations page for exactly which ones, and what each syncs).

How long is information retained?+

See Terms & Conditions, Sections 32–36, for how backups, data export, and post-termination retention work. We do not delete a firm's Client Data simply because a trial expires.

Does TPP use third-party service providers?+

Firms may choose to connect real third-party services — accounting software, e-signature, calendar, payment processors — through the Integrations Hub. Each one is OAuth-based where the vendor supports it, so TPP never sees your password for that service. See the Integrations Center for the full, honestly-labeled list.

What security controls are currently implemented?+

HTTPS everywhere, authenticated staff and client sessions, per-firm data isolation, six-role staff permissions, client-scoped portal access, document visibility flags, per-record activity history, in-portal secure messaging, and mobile biometric login.

What security features are coming soon?+

Client two-factor authentication and SMS reminders are marked Coming Soon. A connected authenticator/SMS provider for verification codes, a unified IP-logged audit trail, encrypted-at-rest document storage, staff MFA enforcement, and passkey sign-in are in development or planned — see the status label on each page.

Security Contact

Security questions?

Contact the TPP team — we route security inquiries to the right people.

Contact the TPP team

Ready to see TPP in action?

30-day free trial. Full access to every feature during your trial, subject to the applicable trial terms.