Why CPAs need secure file transfer
Secure document handling isn't just a best practice. It's a legal and regulatory requirement for tax professionals.
IRS Publication 4557
The IRS's "Safeguarding Taxpayer Data" guide requires tax professionals to create and maintain a written information security plan (WISP). This includes encrypting taxpayer data in transit and at rest, controlling who can access it, and having a data destruction process.
Gramm-Leach-Bliley Act (GLBA)
The FTC's Safeguards Rule under GLBA applies to tax preparers as "financial institutions." It requires you to develop, implement, and maintain a comprehensive security program for customer information: including encryption, access controls, and secure disposal.
Malpractice & E&O liability
A data breach involving client SSNs, EINs, or financial records creates significant malpractice exposure. Courts have found that failing to implement reasonable security measures, when industry guidance exists, constitutes negligence.
Client trust & retention
Clients are increasingly aware of data security. A CPA who can explain their secure document handling process has a tangible competitive advantage over one who says "just email it to me."
What to look for in a secure transfer tool
Not every "secure" file sharing tool meets the bar for handling taxpayer data. Here's the checklist.
Encryption at rest and in transit
Files should be encrypted with AES-256 (or equivalent) when stored, and all transfers should occur over TLS 1.2+. This satisfies both IRS Pub 4557 and GLBA encryption requirements.
Granular access controls
Only authorized parties should access specific documents. Look for per-link or per-document access restrictions rather than broad shared folder permissions.
Audit trails
IRS Pub 4557 expects you to track who accessed taxpayer data and when. Your transfer tool should log access events: downloads, uploads, and failed attempts.
Automatic data destruction
GLBA requires secure disposal of customer information when it's no longer needed. Tools with automatic expiration and deletion help you enforce retention policies without manual cleanup.
Client simplicity
If clients need to create accounts, install software, or navigate complex interfaces, they'll revert to email. The tool should work with a simple link, no client-side setup.
Compliance documentation
Your WISP needs to reference the specific tools and procedures you use. Look for tools that can help you document your security measures for your written plan.
Common mistakes CPAs make
These are the most frequent security gaps we see in accounting practices, and each one creates real liability.
Emailing sensitive documents
Standard email is not encrypted end-to-end. Emails containing SSNs, W-2s, or bank statements can be intercepted, forwarded, or persist indefinitely in sent folders, recipient inboxes, and email backups. IRS Pub 4557 explicitly recommends against this.
Using consumer-grade tools
Dropbox, Google Drive, and WeTransfer are designed for general file sharing, not handling regulated financial data. They lack automatic expiration, granular access logs, and compliant data destruction, features your WISP needs to reference.
No data retention policy
Many firms collect client documents with no plan for when to delete them. Under GLBA, you're required to securely dispose of customer information you no longer need. Indefinite retention increases your breach surface with no benefit.
Sharing passwords over the same channel
Sending a password-protected file and the password in the same email thread defeats the purpose entirely. If the email is compromised, the attacker has both the file and the key. Passwords and files should travel through separate channels.
How DeadVault addresses these requirements
DeadVault was built for exactly this use case, professionals who need to exchange sensitive documents with clients under regulatory constraints.
| Requirement | How DeadVault handles it |
|---|---|
| AES-256 encryption at rest | Every file encrypted with AES-256-GCM using unique per-file keys |
| Encryption in transit | All transfers over TLS 1.2+, no unencrypted endpoints |
| Access controls | Per-link access with optional PIN protection, no shared folder permissions |
| Audit trail | Logged access events, who downloaded what and when |
| Data destruction | Automatic expiration with cryptographic erasure: encryption keys are destroyed, making files permanently unrecoverable |
| Client simplicity | Clients use a simple link: no accounts, no software installs |
DeadVault helps you implement security measures consistent with IRS Pub 4557 and GLBA requirements. It is not a substitute for legal counsel or a comprehensive WISP.
Frequently asked questions
Common questions about secure file transfer requirements for CPAs.
Ready to secure your document workflow?
Start transferring client documents securely in under 2 minutes. No client accounts required.