Security and Compliance

Built for the most sensitive data your clients have.

Tax data is among the most sensitive information your clients hand over. Paloma is built around that from the start, not bolted on after.

AICPA SOC for Service Organizations

SOC 2 compliant

Paloma has completed an independent SOC 2 audit covering security, availability, and confidentiality. The report is available on request.

Why security is the whole ballgame in tax.

Tax documents are breach gold

One client folder holds SSNs, income, addresses, and account numbers - a complete identity-theft kit. Firms are targeted precisely because the payoff is so dense.

Email is the default, and the danger

Left without a better option, clients email their W-2s. Every attachment persists in two inboxes, across relay servers, and in whatever gets forwarded - forever.

Small firm, enterprise obligations

The FTC Safeguards Rule and IRS data-security expectations apply to every tax preparer - not just the ones with an IT department to meet them.

The industry bar

What good security looks like for tax data.

Five pieces of one picture: each standard locks into the next.

FTC Safeguards Rule

Under GLBA, tax preparers count as financial institutions: a written information security plan (WISP), access controls, encryption, and MFA aren't optional extras - they're the legal floor.

IRS Publication 4557

The IRS's own playbook for protecting taxpayer data - covering access management, encryption, monitoring, and incident response for every firm that touches returns.

SOC 2 audits

The standard way software vendors prove their controls: an independent auditor examines security, availability, and confidentiality practices. It's the report firms should ask any vendor about.

Encryption everywhere

Modern practice encrypts data twice over - TLS while it moves, strong encryption while it rests - so interception or stolen storage yields nothing readable.

Multi-factor authentication

The single highest-leverage control there is: a stolen password alone stops working. Regulators now treat MFA as an expectation, not a bonus.

How Paloma handles it

Every control exists because of a pain above.

Breach-gold documents get encryption and field-level protection. The email habit gets replaced by expiring, signed links. And the Safeguards-Rule checklist - MFA, access control, audit trail - is how the platform works by default, not a setting to find.

Paloma

Client documents are protected from upload to handoff, encrypted on the wire and encrypted where they are stored.

Multi-factor authentication

Every account requires MFA, so access is never just a password. Trusted devices are re-verified on a rolling basis.

Role-based access

Your team sees only what their role allows, with least privilege by default. Clients reach their own folders through a separate portal, never yours.

Audit logging

Activity across folders, documents, and accounts is recorded, so there is always an answer to who did what, and when.

Document access runs through signed links that expire on a short clock. Access ends on schedule instead of lingering.

Your data, your control

Clear retention and deletion policies - your firm decides how long client data lives, and when you delete something, it is gone.

Common Questions

Book time with Abby

Have questions about security or compliance? Book 15 minutes with Abby and get straight answers.

Pick a time