Encryption everywhere
AES-256-GCM for SSN/TIN values in an isolated vault, TLS 1.2+ with HSTS in transit, private document storage with short-lived signed links.
Least-privilege access
Roles are stored separately from profiles, granted only by an administrator, and enforced by database row-level security — not by hiding buttons.
Written security plan
A documented Written Information Security Plan (WISP) covering the safeguards IRS Pub. 4557 and the FTC Safeguards Rule require of tax professionals.
Monitoring & response
Access and administrative actions are logged, anomalies raise alerts, and a documented incident response process governs investigation and notification.
IRS requirements for paid preparers
Ascen Tax USA operates under the federal rules that apply to paid tax return preparers and authorized e-file providers.
- PTIN — every individual who prepares or assists in preparing a return for compensation works under a current Preparer Tax Identification Number.
- EFIN — electronic filing is performed through an authorized IRS e-file provider under the e-file rules in Publication 3112 and Publication 1345.
- IRC §7216 — your tax return information is never disclosed or used for a purpose other than preparing and filing your return without your separate, written, revocable consent. Each consent is captured per return and logged.
- Publication 4557 — safeguarding taxpayer data. The technical, administrative and physical safeguards described in our security plan map to this publication.
- Circular 230 — practice standards for due diligence, conflicts of interest and record retention.
- Six-year record keeping — return copies and the required preparer records are retained for the period the IRS and applicable states require.
GLBA and the FTC Safeguards Rule
Tax preparation firms are financial institutions under the Gramm-Leach-Bliley Act, so the FTC Safeguards Rule (16 CFR Part 314) applies to us in full.
- A designated qualified individual is accountable for the information security program.
- A written risk assessment identifies foreseeable internal and external risks to customer information.
- Access controls, encryption of customer information at rest and in transit, multi-factor authentication for staff, and secure disposal of data no longer needed.
- Change management, logging and monitoring of authorized user activity, and periodic testing of controls.
- Service provider oversight through written agreements and review of the safeguards our processors maintain.
- Incident response plan and reporting of qualifying security events to the FTC as the rule requires.
- An annual privacy notice describing what we collect, why, and the limited circumstances in which it is shared.
State privacy and state tax rules
In addition to federal law, we honour the individual rights created by US state privacy statutes for residents of states where those laws apply, including California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah and Texas.
- We do not sell your personal information and we do not share it for cross-context behavioural advertising.
- You may request access to, correction of, a portable copy of, or deletion of your personal information, subject to the tax records we are legally required to keep.
- We will not discriminate against you for exercising a privacy right.
- State breach notification laws are followed in every state where an affected taxpayer resides, alongside the IRS and state tax agency notification steps for suspected preparer data theft.
- State e-file rules and state preparer registration requirements (for example California CTEC, Oregon, New York and Maryland) are respected where they apply to the work we perform.
If something goes wrong
We maintain a written incident response plan. If taxpayer data is affected, we contain and investigate first, then notify quickly and clearly.
- Immediate containment: revoke sessions and tokens, isolate affected accounts, preserve logs for investigation.
- Notification to the IRS Stakeholder Liaison and the affected state tax agencies, as Publication 4557 directs for preparer data theft.
- Notification to affected taxpayers and, where required, to state attorneys general and the FTC, within the applicable statutory deadlines.
- Post-incident review with corrective actions tracked to completion.
What we are working on next
We publish our roadmap so you can see where the programme is heading rather than only what is finished.
- Independent penetration test and remediation cycle, repeated annually.
- SOC 2 Type II readiness assessment followed by a full audit.
- WCAG 2.2 AA accessibility audit of the taxpayer portal.
- Formal key-rotation schedule and documented vendor security reviews.
Policy library
Every document that governs how we handle your information.
Report a concern
Security questions, privacy requests and vulnerability reports go to Mehul Shah at tax@ascentaxus.com or (816) 294-5633. Mailing address: 10124 N McKinley Drive, Kansas City MO 64157. Please do not include full Social Security numbers in an email — sign in to the portal instead.