Security and data handling
Plain answers to the questions a firm's IT lead and managing partner ask.
Everything here is what the system actually does.
- Who touches the return
- Nobody. Your staff upload directly into your firm workspace over TLS. Processing is automated end to end; no CitedTax employee handles the file.
- Identifiers removed before analysis
- Social Security / ITIN, EIN, bank routing and account numbers, phone numbers and email addresses are replaced with placeholders before any text is analyzed. Dollar figures and form data are untouched. Names are not needed for the analysis and never appear in the report unless your CPA types a client name at review time.
- Encryption
- TLS in transit. At rest, every stored object is encrypted with a key unique to your firm (AES-256-GCM) on top of the storage provider's own encryption.
- What we keep, and for how long
- The uploaded PDF is deleted as soon as the analysis has extracted what it needs (default; a 7-day option exists for re-runs). Working papers and client reports are kept for 90 days by default; your firm can shorten this, and an administrator can purge everything at any time.
- Where analysis runs
- On our servers and our AI model provider's API under commercial terms that do not permit training on your data. Location and retention commitments are stated in the data-processing terms you sign.
- No training, no reuse
- Your data is used solely to produce your firm's reports. It is never used to train models, never aggregated across firms, and never sold or shared.
- Access control
- Every user signs in with multi-factor authentication. Roles: administrator (billing, branding, users, retention) and preparer (upload, review, download). Every upload, download, approval and purge is written to an audit log your administrator can export.
- Professional responsibility
- CitedTax is a research tool. Its output is graded evidence for the reviewing CPA. Items graded "CPA to confirm" cannot be placed in a client report until the CPA marks them confirmed. The client report is your firm's document.
- Subprocessors
- Hosting (Vercel), database (Neon), object storage (Vercel Blob), AI model provider, embeddings and law-text index (Voyage AI, Upstash; queries only, never the return), payments (Stripe), email (Resend), product analytics on the public site and app navigation only (PostHog: no return data, no client names, no session recording), scheduling for walkthroughs (Cal.com, public site only), and e-signature for our agreements with your firm (Documenso). Each is under a data-processing agreement.
- Your compliance file
- On request we provide a security summary suitable for your written information security plan (FTC Safeguards Rule / IRS Publication 4557 vendor review) and our data-processing addendum, including our position under IRC §7216.
Questions: security@citedtax.com