Security and Compliance
Tax data is among the most sensitive information your clients hand over. Paloma is built around that from the start, not bolted on after.
One client folder holds SSNs, income, addresses, and account numbers - a complete identity-theft kit. Firms are targeted precisely because the payoff is so dense.
Left without a better option, clients email their W-2s. Every attachment persists in two inboxes, across relay servers, and in whatever gets forwarded - forever.
The FTC Safeguards Rule and IRS data-security expectations apply to every tax preparer - not just the ones with an IT department to meet them.
The industry bar
Five pieces of one picture: each standard locks into the next.
Under GLBA, tax preparers count as financial institutions: a written information security plan (WISP), access controls, encryption, and MFA aren't optional extras - they're the legal floor.
The IRS's own playbook for protecting taxpayer data - covering access management, encryption, monitoring, and incident response for every firm that touches returns.
The standard way software vendors prove their controls: an independent auditor examines security, availability, and confidentiality practices. It's the report firms should ask any vendor about.
Modern practice encrypts data twice over - TLS while it moves, strong encryption while it rests - so interception or stolen storage yields nothing readable.
The single highest-leverage control there is: a stolen password alone stops working. Regulators now treat MFA as an expectation, not a bonus.
How Paloma handles it
Breach-gold documents get encryption and field-level protection. The email habit gets replaced by expiring, signed links. And the Safeguards-Rule checklist - MFA, access control, audit trail - is how the platform works by default, not a setting to find.

Client documents are protected from upload to handoff, encrypted on the wire and encrypted where they are stored.
Every account requires MFA, so access is never just a password. Trusted devices are re-verified on a rolling basis.
Your team sees only what their role allows, with least privilege by default. Clients reach their own folders through a separate portal, never yours.
Activity across folders, documents, and accounts is recorded, so there is always an answer to who did what, and when.
Document access runs through signed links that expire on a short clock. Access ends on schedule instead of lingering.
Clear retention and deletion policies - your firm decides how long client data lives, and when you delete something, it is gone.
Common Questions
Have questions about security or compliance? Book 15 minutes with Abby and get straight answers.
Pick a time