
Document ID: TFP-SEC-SOC2-2026
Issued: January 2026 · Valid Through: January 2027
Security & Compliance Attestation Report
This document provides enterprise tax clients with a comprehensive overview of TaxFlow Pro's SOC 2 Type II certification, security architecture, trust service principles, and operational controls. It is designed to satisfy vendor security review and procurement requirements for corporate, high-net-worth, and institutional tax engagements.
Executive Summary
TaxFlow Pro, powered by PDAC Media, is built on the HighLevel platform — which holds SOC 2 Type II certification following an independent third-party audit conducted in accordance with the AICPA Trust Services Criteria. This attestation confirms that the information security controls of the underlying platform — covering document intake, taxpayer onboarding, Voice AI receptionist systems, and practice CRM infrastructure — operate with effectiveness over a continuous monitoring period, and that TaxFlow Pro inherits these protections for every taxpayer record your office processes. Tax preparers and enterprise clients can rely on TaxFlow Pro to handle sensitive taxpayer data with bank-grade security protocols aligned with IRS Publication 4557 and FTC Safeguards Rule best practices.
Trust Service Principles
Security
Information and systems are protected against unauthorized access, unauthorized disclosure of information, and damage to systems that could compromise the availability, integrity, and confidentiality of taxpayer data.
Availability
Information and systems are available for operation and use to meet the practice's objectives, with multi-region redundant cloud infrastructure ensuring 99.99% uptime — even during peak April filing deadlines.
Confidentiality
Information designated as confidential is protected to meet the practice's objectives. All W-2s, 1099s, SSNs, and tax return files are encrypted in transit and at rest with zero unauthorized personnel access.
Processing Integrity
System processing is complete, valid, accurate, timely, and authorized. Document intake and organization pipelines include human-in-the-loop review to maintain data integrity.
Operational Security Controls
The following controls have been independently verified as operating effectively throughout the audit monitoring period:
Data Architecture & Encryption
Encryption at Rest & in Transit
All taxpayer documents (W-2, 1099, K-1, 1040) are encrypted using AES-256-bit encryption at rest within isolated cloud vaults. Data in transit is protected via TLS 1.3 with certificate pinning. Encryption keys are managed via a dedicated KMS with automatic rotation every 90 days.
Multi-Region Redundancy
TaxFlow Pro infrastructure is deployed across geographically separated availability zones with automated failover. This ensures uninterrupted document intake and Voice AI receptionist availability during peak tax season, even in the event of a regional outage.
Access Governance
All system access is governed by role-based access controls (RBAC) with least-privilege provisioning. Multi-factor authentication is mandatory. Access logs are immutable and retained for a minimum of 12 months for audit purposes.
Attestation Statement
AICPA SOC 2 Type II — Verified Operational Security
"TaxFlow Pro is built on the HighLevel platform, which has been independently audited and certified as compliant with the AICPA Trust Services Criteria for Security, Availability, and Confidentiality under SOC 2 Type II. This attestation verifies that the controls described in this document were suitably designed and operated effectively throughout the monitoring period to meet the applicable trust services criteria — and that TaxFlow Pro delivers those same protections to your tax office."