Accounting & Tax AI

TaxGPT

Medium risk

AI tax research copilot for accountants and tax professionals: cited tax answers, document analysis, memo drafting, and autonomous workflow agents.

Verified 2026-08-31TaxGPT Inc.www.taxgpt.com

Is TaxGPT safe for confidential data?

TaxGPT publishes a stronger security story than most young AI vendors — SOC 2 Type II, AES-256 encryption in transit and at rest, automatic PII redaction on client data, and an unambiguous no-training policy stated on its security page. The reasons it still sits at medium rather than low: it is a newer company whose claims rest on its own attestations rather than a long audit history, its Data Processing Addendum terms need to be confirmed rather than assumed, and the data it handles — client tax returns, IRS notices, SSNs — is exactly the category IRS Publication 4557 and the FTC Safeguards Rule require preparers to inventory and protect under a written information security plan (WISP). If your firm adopts it, adopt it on paper: signed terms, WISP entry, and a rule about what staff may upload.

Risk by plan

The same product often carries very different terms depending on the tier — consumer plans are where the exposure concentrates.

Individual / trial
No training

Same published no-training policy as paid plans, but trial use often happens before any firm agreement is signed — bring it under contract before client data goes in.

Firm / Enterprise
No training

Adds firm-level administration; the DPA and security terms should be executed at this level.

Data handling

Training on inputs

TaxGPT states it does not train AI models on user or firm data at all — no opt-out is needed because, per its security page, no such training occurs on any plan.

Retention

TaxGPT does not publish specific retention windows on its security page; it references a Data Processing Addendum and privacy policy — confirm deletion timelines in your agreement.

Residency

Data is stored in the United States on third-party hosted infrastructure (AWS and Azure) that TaxGPT describes as SOC 2 Type II compliant. No Canadian or EU residency option is published.

Compliance

  • SOC 2Yes
  • GDPR / DPAConditional
  • HIPAA BAANot verified

Certifications typically apply to specific tiers and contracts — confirm scope in writing before relying on them.

New to these frameworks? See our plain-language guides to SOC 2 and the other AI compliance standards.

Enterprise controls

  • Automatic PII redaction on client data
  • AES-256 encryption at rest and in transit
  • SOC 2 Type II attestation
  • Published Data Processing Addendum

Frequently asked questions

Is TaxGPT safe for client tax data?

Its published controls are genuinely good for the category: SOC 2 Type II, encryption everywhere, automatic PII redaction, and a blanket no-training policy. Safe still depends on your side of the ledger — a signed agreement, an entry in your WISP as IRS Publication 4557 expects, and staff guidance on what gets uploaded. The vendor posture is not the weak point; undocumented adoption is.

Can I put client tax data in TaxGPT?

Under a signed firm agreement, yes, with normal precautions: TaxGPT states client data is encrypted, PII is automatically redacted, and nothing is used for model training. Note that data is processed in the United States, so Canadian preparers should weigh PIPEDA cross-border disclosure expectations, and Section 7216 consent rules still govern any disclosure of US return information.

Does using a tax AI tool satisfy my WISP obligations?

No — it adds to them. Every preparer subject to the FTC Safeguards Rule must maintain a written information security plan, and each AI tool that touches taxpayer data belongs in it, with an owner and an access rule. The more common gap is the reverse: staff using free general-purpose chatbots for tax questions outside any agreement, which no vendor's SOC 2 report can cover.

Policy changelog

  • Initial entry published from TaxGPT's published security documentation and IRS safeguarding guidance.

Sources

This profile summarizes the vendor's published policies as of the verification date. It is not legal advice.

TaxGPT is probably already in your organization.

Sanitized AI shows you who is using it and redacts sensitive data from prompts before it leaves your control.

Get a demo

More AI tool profiles