R&A Pro-Tax is built for tax-office operations that handle the most sensitive taxpayer data. Every layer — from credential storage to lifecycle governance — is encrypted, audited, and aligned with IRS Publication 4557, the FTC Safeguards Rule, and the Gramm-Leach-Bliley Act.
All data at rest is encrypted with AES-256. All traffic is protected with TLS 1.2+.
Least-privilege RBAC across super-admin, office admin, preparer, and client roles.
Row-level security enforces strict cross-tenant isolation — no office sees another's data.
Sensitive credentials are masked by default. Every reveal is logged with user, IP, and timestamp.
Every privileged operation — credential reveal, document upload, lifecycle transition, impersonation — is recorded immutably.
Verification decisions, document approvals, and compliance state changes are write-once and tamper-evident.
All office documents are stored in private buckets with signed URLs and tenant-scoped access policies.
Onboarding, activation, suspension, and reinstatement follow enforced state machines with super-admin oversight.
Banking, credentials, and compliance items are verified by a super-admin before activation.
Every credential and document tracks issue date, expiration, and renewal cadence — alerts fire automatically.
Per-season renewal workflows, escalation cadences, and automated reminder dispatch keep offices compliant.
Documented incident response process covering investigation, containment, and statutory breach notification.
Our written information security plan (WISP), access controls, and audit trails are designed against the published safeguards for taxpayer data. Read our full security policy for technical details.