Independently audited by a third party
WebEASM · AEGISonar external attack-surface assessment Overall Grade 5 (Safe)
ALL IN ONE PORTAL
Everything your firm needs, in one portal
Beyond secure exchange — requests, signatures, payments, and messaging for the whole season, all in one place.
Secure document exchange
Snap a photo and it travels encrypted, end to end. No more email attachments.
3 languages · live translation
English, Korean, and Spanish. Preparer and client each write in their own language — messages translate automatically.
E-signature
Sign engagement letters, POAs and other standard documents right in the portal. No printing, no scanning.
Invoicing & payments · 0% fee
Collect by card or bank transfer (ACH) with automatic receipts — plus pay-to-unlock documents that open only after payment.
Document requests · due dates
Send a checklist of what you need, with due dates and D-day badges. Unsubmitted items are chased automatically.
Tax organizer
The standard 16 questions plus your own custom ones. Clients answer in their own language.
Permanent documents
ID, SSN card, and other year-after-year files stay in one place, independent of tax year.
Text (SMS) alerts
For clients who never open email. Opt-in only, and one STOP reply ends it.
Easy onboarding
Move your existing client list in minutes by paste or CSV. Your dedicated portal is created the moment you subscribe.
SECURITY BY DESIGN
Security is the architecture, not a feature
A system that handles taxpayer data can’t rely on “being careful.” TaxPin enforces the safeguards below at the database layer — they are not options that can be switched off.
Encrypted in transit & at rest
Every document travels over TLS and is stored with AES-256 encryption. Plaintext files never sit anywhere on our servers.
Complete firm-to-firm isolation
Multi-tenant isolation is enforced by database row-level security (RLS), not application code. A query against another firm’s data is impossible by construction.
Expiring signed links
There are no permanent public URLs. Every view and download goes through a signed link that expires within minutes.
Two-factor authentication (MFA)
Authenticator-app MFA is available to both preparers and clients — and once enrolled, the database itself requires it. A password alone cannot reach the data.
Tamper-proof audit log
Uploads, downloads, deletions, profile changes, and consent changes are recorded automatically. The log is append-only — it cannot be edited or erased.
Automatic sign-out
Sessions end after 30 minutes of inactivity. Nothing lingers on a shared computer.
No documents in email
Notification emails never carry attachments — only “check your portal.” Even a compromised inbox exposes no documents.
Adversarial security review
The design has been hardened through attack-scenario reviews: tenant-isolation bypass, privilege escalation, invite hijacking, and more.
Compared to email attachments
IRS Publication 4557 and the FTC Safeguards Rule (16 CFR Part 314) require encryption, multi-factor authentication, and access logging for taxpayer data — a standard email attachments simply cannot meet.
Compliance posture
