Security First

Your Client Data, Protected

Enterprise-grade security and privacy practices designed for CPA firms across the US and Canada handling sensitive tax and financial data — aligned with PIPEDA, CCPA, GLBA, and IRS Publication 4557.

256-bit
AES Encryption
99.9%
Uptime SLA
PIPEDA · CCPA
GLBA · Pub 4557 aligned
SOC 2
Aligned
Data Protection

Your Data is Encrypted at Every Layer ENSURES COMPLIANCE

Multiple layers of encryption and security ensure your clients' sensitive financial information is protected at all times.

Encryption in Transit

All data transmitted between your browser and our servers is protected with TLS 1.2+ encryption. Every API call, file upload, and page load is secured with industry-standard transport layer security.

256-bit bank-grade encryption

Encryption at Rest

All stored data, including client records, tax documents, and financial information, is encrypted using AES-256 encryption. Even in the unlikely event of unauthorized physical access, your data remains unreadable.

AES-256 at-rest protection

Enterprise-Grade Cloud Hosting

Your data is hosted on Microsoft Azure with regional redundancy. Canadian tenants can elect Canadian Azure regions to satisfy data residency expectations; US tenants can elect US Azure regions for IRS Publication 4557 alignment. Your clients' information stays within your chosen jurisdiction unless you explicitly export it.

US & CA regional Azure hosting

Encrypted Credential Storage

Each firm's SMTP, SMS, and integration credentials are encrypted with dedicated AES-256 keys. Credentials are decrypted only at the moment of use and never stored in plaintext or shared between firms.

0 plain-text passwords

Automatic Backups

Your data is automatically backed up on a regular schedule with point-in-time recovery capabilities. Backups are encrypted and stored in geographically separate locations to protect against data loss from any single point of failure.

Daily point-in-time recovery
Access Control

Granular Access Controls ENSURES COMPLIANCE

Ensure the right people see the right data with role-based permissions, two-factor authentication, and comprehensive audit trails.

Role-Based Access

Four distinct permission levels ensure staff only access what they need.

  • Admin - Full system access
  • Manager - Team and client management
  • Staff - Assigned client access
  • ReadOnly - View-only access
4 configurable role levels

Two-Factor Authentication

Protect accounts with OTP verification delivered via email or SMS for every login.

  • Email-based OTP codes
  • SMS-based OTP codes
  • Configurable device remembrance
  • Adjustable expiry (1 hour to 1 week)
99.9% of attacks prevented

Session Management & Audit Logging

Automatic session timeouts and comprehensive logging of all user activity.

  • Automatic session timeout
  • Login and action audit trail
  • IP and device tracking
  • Security event notifications
Every action logged
Multi-Office Data Isolation

Complete Firm Isolation PROTECTS REVENUE

Every office and branch on MyCPACRM operates in a completely isolated environment. There is zero possibility of data crossing between offices.

Complete Data Isolation

Every database query is automatically filtered by firm. It is architecturally impossible for one firm to access another firm's client data, filings, documents, or communications.

0 cross-firm data access

Separate SMTP & SMS Credentials

Each firm configures their own email server and SMS provider. Client communications are always sent from your firm's own credentials, never from a shared system or another firm's configuration.

Per-firm secure isolation

Firm-Specific Storage

Document uploads and file storage are organized into firm-specific buckets. Access controls ensure documents uploaded by one firm cannot be accessed or enumerated by any other firm.

Separate containers per firm

Zero Cross-Firm Leakage

Background jobs, automated reminders, and scheduled tasks all verify firm context before execution. Each operation is scoped to a single firm with explicit security checks to prevent any cross-contamination.

0 incidents since launch
PIPEDA · CCPA · GLBA Aligned

Built for North-American Privacy Law ENSURES COMPLIANCE

MyCPACRM is designed from the ground up to meet the privacy expectations of accounting firms in both Canada and the US. Canadian firms get alignment with the Personal Information Protection and Electronic Documents Act (PIPEDA) — Canada's federal privacy law governing how private-sector organizations collect, use, and disclose personal information.

US firms get alignment with the California Consumer Privacy Act (CCPA / CPRA), Virginia's VCCPA and similar state laws, the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule for financial institutions, and IRS Publication 4557 ("Safeguarding Taxpayer Data") — the IRS's specific guidance for tax practitioners.

Personal Information Protection

All personally identifiable information — SSN and EIN (US), SIN and BN (Canada), addresses, banking, and financial data — is encrypted and access-controlled at the field level.

Right to Access & Correct Data

Clients can request access to their personal information and have inaccuracies corrected at any time.

Data Export Capabilities

Export client data in CSV and PDF formats for portability, regulatory review, or migration purposes.

Data Retention Policies

Configurable retention policies ensure data is kept only as long as necessary and securely disposed of when no longer required.

Consent Management

Track and manage client consent for data collection, email communications, and SMS reminders with clear opt-in and opt-out controls.

Privacy by Design

Security and privacy considerations are built into every feature from the architectural design phase, not bolted on after the fact.

Infrastructure

Secure, Reliable Infrastructure PROTECTS REVENUE

Built on modern, hardened infrastructure with multiple layers of protection to ensure your practice runs without interruption.

Secure Cloud Hosting

Hosted on enterprise-grade cloud infrastructure

Regular Updates

Continuous security patches and updates

DDoS Protection

Protection against distributed attacks

SSL/TLS Everywhere

All connections encrypted end-to-end

24/7 Monitoring

Automated alerting and uptime monitoring

Compliance & Standards ENSURES COMPLIANCE

MyCPACRM aligns with the security frameworks and compliance standards that matter most to accounting firms across the US and Canada.

PIPEDA & CPA Canada

Aligned with the Personal Information Protection and Electronic Documents Act (Canada's federal privacy law) and CPA Canada's data-handling best practices for professional accounting engagements.

Canada privacy & professional standards

CCPA · GLBA · IRS Pub 4557

Aligned with the California Consumer Privacy Act (CCPA / CPRA) and similar state privacy laws, the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule, and IRS Publication 4557 — the IRS's data-security guidance for tax practitioners.

United States privacy & taxpayer-data security

OWASP Top 10 Protection

Protected against the OWASP Top 10 most critical web application security risks, including injection attacks, broken authentication, cross-site scripting, and insecure deserialization.

Top 10 vulnerability protection

Security FAQs

Common questions about how we protect your data.

Where is my data stored?

Your data is stored on Microsoft Azure with regional redundancy. Canadian tenants can elect Canadian Azure regions; US tenants can elect US Azure regions, satisfying data-residency expectations under PIPEDA in Canada and IRS Publication 4557 in the US. All data at rest is encrypted with AES-256, all transit with TLS 1.3, and we maintain regular encrypted backups (30-day retention). Your client information never leaves your chosen jurisdiction unless you explicitly export it.

Who can access my client data?

Only authorized users within your firm can access your client data, based on their assigned role (Admin, Manager, Staff, or ReadOnly). MyCPACRM support staff do not have access to your client data. Our architecture ensures complete isolation between offices, and all access is protected by two-factor authentication.

What happens if I cancel my subscription?

If you cancel, you will have a grace period to export all your data in standard formats (CSV, PDF). After the grace period, your data is securely deleted from our servers and backups in accordance with our data retention policy. We provide clear instructions and tools to ensure a smooth transition.

Do you sell or share client data?

Absolutely not. We will never sell, share, rent, or trade your client data to any third party. Your data is yours. We only process it as necessary to provide the MyCPACRM service to your firm, and we are fully transparent about our data practices in our Privacy Policy.

Your Security Matters

Questions About Security?

We're happy to discuss our security measures in detail. Reach out to learn how MyCPACRM keeps your firm's data safe.