Security & data handling
How VouchDoc protects your clients' tax documents — written to be printed and handed to your E&O carrier, your IT reviewer, or a client who asks.
VouchDoc · vouchdoc.com · Last updated July 2026
In one line
VouchDoc replaces unencrypted email attachments as the way tax documents reach your desk. Clients upload through an encrypted portal with no account to create; documents are stored encrypted in US data centers, reachable only by your firm, deleted on a schedule you set, and every access is logged.
Encryption & access control
- In transit
- Every upload and every page load travels over TLS. Clients upload directly to encrypted storage — documents are never sent as email attachments.
- At rest
- All stored documents and database records are encrypted at rest (AES-256).
- Social Security numbers
- Encrypted individually at the field level (AES-256-GCM) on top of the encryption above. Displayed as XXX-XX-1234; revealing one is decrypted server-side and written to the audit trail with the user and timestamp. SSNs never appear in logs, error reports, analytics or email.
- Who can sign in
- Two-factor authentication is mandatory for every firm user — a one-time code by email, or an authenticator app. Each firm's data is isolated at the database level, so one firm can never read another's.
- How clients get in
- Each client receives one cryptographically signed link that expires after 30 days and can be revoked at any time. Clients create no account and hold no password — there are no client credentials to be phished or reused.
- What is recorded
- Logins, uploads, downloads, edits, SSN reveals, exports, link revocations and deletions are written to an append-only audit trail scoped to your firm.
Where your clients' data is processed
No taxpayer document, and no data extracted from one, leaves the United States. Storage, hosting and email all run in US regions; the one extraction resource still pending its move is noted below, and it has never received a client document. Each subprocessor below operates under a signed data processing agreement; this is the complete list.
| Purpose | Provider | Region | Assurance |
|---|---|---|---|
| Database, document storage | Supabase | US East | SOC 2 Type II · DPA signed |
| Application & API hosting | Vercel | US East (iad1) | DPA signed |
| Document data extraction | Microsoft Azure AI | US East (at launch — see below) | SOC 2 · DPA signed · no training on your data |
| Transactional email | Resend | United States | DPA signed |
| Subscription billing | Stripe | United States | DPA signed · never receives tax documents |
Automated data extraction
VouchDoc reads the figures off W-2s and 1099s using Microsoft Azure's prebuilt tax models — a fixed, pre-trained service, not a general-purpose chatbot.
- · Microsoft does not use data sent to its prebuilt models to train them. Your clients' documents never become training data — for Microsoft or for us.
- · No human reviews your documents at any point in the process.
- · Azure deletes the analysis results within 24 hours.
- · Documents are transmitted as bytes over an authenticated connection. No third-party service ever receives a link to your storage.
- · Extracted figures are yours: nothing is sold, shared, pooled across firms, or used for any purpose other than producing your export.
Retention & deletion
These are the limits we hold ourselves to, and the shortest ones we can operate on. You set the retention window for documents; the rest are fixed. Deletions are recorded in the audit trail, and you can request an earlier purge at any time.
| Data | Kept for | Notes |
|---|---|---|
| Documents & extracted data | 16 months after the end of the tax season they belong to | Configurable 3–36 months per firm |
| Exports (the only file containing a clear SSN) | 7 days | Download link expires after 15 minutes |
| Audit trail | 3 years | Append-only |
| Trial account never converted | 90 days | Complete purge |
| Closed account | 30-day grace period | Full ZIP export offered, then permanent deletion |
| Encrypted backups | 7 days (point-in-time recovery) | Restore tested quarterly |
If something goes wrong
Our incident procedure is written down: contain (rotate keys, revoke client links, disable the portal if needed), scope the exposure through the audit trail, then notify every affected firm within 72 hours with the facts and the actions taken — along with a ready-to-send notice for your own clients, following IRS Pub. 4557. Every incident ends in a written postmortem. Security contact: security@vouchdoc.com.
For your WISP
Every PTIN holder attests to having a Written Information Security Plan. Client document collection is one of its hardest sections to write honestly. If VouchDoc is how your documents come in, this paragraph can be pasted as is:
Client document collection (VouchDoc). Client tax documents are collected exclusively through VouchDoc, an encrypted client portal. Clients upload documents over TLS; files are encrypted at rest, Social Security Numbers are additionally encrypted at the field level, and access requires multi-factor authentication. No taxpayer documents or SSNs are exchanged over unencrypted email. Access is logged and data is retained only as long as needed and then securely purged.
What we do not claim
- VouchDoc is not SOC 2 certified. The infrastructure we run on is (Supabase, Microsoft Azure); our own SOC 2 Type I audit is on the roadmap, not completed. We would rather tell you than let a vendor logo imply otherwise.
- Retention is enforced by hand during beta. The windows in the table above are the policy we operate to, and deletion on request is immediate — but the scheduled job that applies them automatically is not built yet, and backup restores have not been rehearsed on a quarterly cycle. Both land before we hold production data for paying firms.
- Our extraction resource is not yet in a US region. During beta, document extraction points at a development Azure resource hosted in Europe, and it processes synthetic test files only — no client document has ever reached it. The US East production resource is provisioned before any real taxpayer document is extracted. We are telling you now rather than after.
- Cyber liability insurance will be in place before we open to paying firms. If you are reading this during our beta, ask us for the current status and we will answer plainly.
- This is not legal or tax advice. Your obligations under IRC §7216, the FTC Safeguards Rule and your own WISP remain yours. VouchDoc is document-collection infrastructure — like your tax software, your scanner or your cloud storage — and does not prepare returns. Confirm your specific situation with your advisor or E&O carrier.
Questions this page doesn't answer — from you, your IT reviewer or your carrier — go to security@vouchdoc.com. A person answers, usually the same day.
VouchDoc · vouchdoc.com · Security & data handling · Last updated July 2026