For accounting & CPA firms

AI in every workflow. Client data in none of them.

A six-person tax practice or a 300-person firm: same install, same afternoon. PrivacyPal is the on-device governance layer that lets preparers, bookkeepers, auditors and advisory staff use ChatGPT, Claude, Copilot, Gemini, Grok and Perplexity on live client work. Taxpayer names, SSNs, EINs, account numbers and wage detail are swapped before anything leaves the device. Section 7216, the FTC Safeguards Rule and AICPA confidentiality stop being the reason your firm says no to AI.

CPA reviewing a client return with PrivacyPal-protected AI
The consent problem

Your client never consented to that paste

Section 7216 makes it a criminal matter for a return preparer to disclose or use tax return information without the taxpayer's written consent. A staff accountant dropping a K-1 into a public chatbot is a disclosure: a misdemeanor carrying up to $1,000 and a year, plus $250 per disclosure under Section 6713. The AICPA's Confidential Client Information Rule says the same thing in professional terms, and the FTC Safeguards Rule already requires a written plan naming who may touch client data and where it goes.

Nobody in your firm is trying to breach any of that. They are trying to finish a return at 9pm in March. PrivacyPal makes the compliant path the default path: staff keep the AI, client identity never crosses the perimeter, and every prompt lands in a log your peer reviewer, your insurer and your clients can be shown.

47types
Of sensitive data detected out of the box, SSNs, EINs and bank details included.
0bytes
Of real client data sent to any AI provider. The mapping stays on the device.
7platforms
Chat apps and agent surfaces governed under one firm policy.
01 · Inside the practice
"Review the 2025 Form 1040 for Margaret A. Whitfield, SSN 412-88-7305, filing jointly with David R. Whitfield of 1428 Foxglove Lane, Ashford, CT. Schedule K-1 from Harborline Dental Partners LLC, EIN 47-3392085, ordinary business income $418,400. Prior-year NOL carryforward $96,250. Flag anything that changes the QBI calculation."
02 · Privacy Twin · what the model sees
"Review the 2025 Form 1040 for Katherine L. Ashgrove, SSN 307-54-1962, filing jointly with Michael J. Ashgrove of 2207 Marigold Avenue, Brookvale, OR. Schedule K-1 from Ridgeway Optical Group LLC, EIN 82-6047319, ordinary business income $361,750. Prior-year NOL carryforward $83,900. Flag anything that changes the QBI calculation."

10 swaps in one prompt: names, SSN, EIN, entity, address, amounts · answer comes back with the real values restored · no Section 7216 disclosure occurs · every touch logged

Where firms deploy it

Every service line, one policy

Tax preparation & review

Run AI over real 1040s, 1120s and K-1s. Taxpayer names, SSNs, ITINs, EINs and addresses are swapped before the model reads a single line.

Bookkeeping & client accounting

Month-end close, reconciliations, cleanup work. Vendor names, payroll detail and bank account numbers stay inside the practice.

Tax strategy & CFO advisory

Model entity structures, distributions and planning scenarios on the client's real numbers. Turn financial twins off and the math stays exact while identity stays protected.

Audit & assurance

Summarize workpapers, draft testing memos, interrogate a trial balance. Client identity and non-public results never reach an outside model.

Beyond the tax stack

The tax copilots cover tax. Your firm does more than tax.

Blue J, TaxGPT and the rest are good at the job they were built for: a research question, a citation, a memo. Then a preparer opens Claude to rewrite a client email with the client's numbers still in it. An admin drops a scanned W-2 into ChatGPT to pull the figures out. A partner runs Perplexity over a prospect. Someone points an agent at the engagement folder and walks away. That is where firm data actually goes, and no tax-specific tool is watching any of it.

PrivacyPal does not replace those tools. It governs everything around them, so the AI your people reach for at 9pm is held to the same policy as the AI your firm formally approved.

Every chat platform

ChatGPT, Claude, Gemini, Copilot, Grok and Perplexity, intercepted on the device before a prompt leaves it. When the firm adopts the next one, the policy does not have to be rewritten.

Agents, not just chat

Claude Code, Copilot agents, Hermes Agent and Private MCP run under the same firm policy. What an agent may read, write and send out is a setting, not a hope. Max only.

The AI nobody told you about

On-device DSPM and shadow AI discovery surface the tools your staff signed up for on their own, while there is still time to do something about it.

Systems of record

Your ledger is not training data

Client PII is the obvious asset. It is not the only one. The firm's real property is the work product: the tax strategies refined over twenty years, the engagement templates, the pricing model, the client list, the workpaper methodology nobody else has. All of it sits in a system of record, the general ledger, the practice management system, the tax software, the client portal, and all of it is one automation away from being pasted into somebody's model.

PrivacyPal is the only governance layer that protects the firm's own intellectual property at the same moment it protects the client's identity, on the device, before either one leaves. Connect the systems of record and the data stays in them.

Connections

PrivacyPal learns what is sensitive at the source, so it is recognized the moment it surfaces in any AI, in a prompt, a paste or an agent's tool call. Salesforce, Slack, Workday, Oracle ERP and financials, Notion, Google Drive, SQL, Google Docs and Word ship today.

Private MCP for the ledger

The sanctioned route for an agent to reach an internal system without that connection leaking to a public host. The model works on twins, the system of record sends and receives real values, your people see the real answer. NetSuite, Intuit and your practice management stack connect this way: build it with @privacypal/private-mcp or with us.

On-device DSPM

The exported trial balance, the downloaded return, the client file somebody saved to the desktop in February. Classified where it sits, on staff laptops, before any model gets near it.

One policy from the ledger to the prompt · systems of record keep their data · agents get the context, never the underlying values

vs. the status quo

An AI policy is not AI governance

Most firms wrote the memo, circulated the acknowledgement form and moved on. A signed form tells you what staff agreed to. It does not tell you what they pasted.

ApproachProductivityClient data exposureEvidence for review
Ban AI in the practiceNear zero. Staff use it on their phones.Unknown: no visibilityNo
Signed AI policy on fileUnchanged. The judgment call sits with each preparer.One paste away, every timeA signature, not a log
PrivacyPalEvery tool, every preparerZero: swapped before sendPer-prompt, exportable, SIEM-ready
Busy season

Your roster changes. Your obligations do not.

Between January and April the firm is a different firm: seasonal preparers, contract reviewers, an offshore team carrying the volume overnight. Every one of them is a disclosure decision under Section 7216 and a third-party service provider question under the AICPA rules.

PrivacyPal Max attaches to the firm domain and provisions each of those seats centrally, on whichever device and in whichever country it sits. Onboard in October, deprovision in May, and hold the identical policy for a partner in the office and a preparer eight time zones away. Nobody has to remember the rule, because the rule is enforced at the device.

Accounting-first

Built for how a practice actually runs

Financial twins, your call

Dollar amounts are twinned by default. Switch financial twins off in Settings and money values pass through untouched, so a strategy calculation stays exact. Names, SSNs, EINs, account numbers and dates keep full protection either way. Per user, not per firm.

Evidence, not assurances

Every prompt, every file, every AI surface, logged with who touched what and from which device. Export it into the written information security plan the Safeguards Rule already requires of you.

Every device the work happens on

Mac, Windows and the browser, governed the same way. The home PC a preparer uses in March and the office laptop they use in June are one seat, one policy, one audit trail.

Which plan

Firms run PrivacyPal Max

Max covers everyone who touches a client file: attach the firm domain, provision partners, preparers, bookkeepers and seasonal staff centrally, and hold one confidentiality policy across every service line. $30 per seat a month at 1 to 9 seats, $25 at 10, $21 at 100, billed annually. A sole practitioner covering only themselves runs Pro at $7.50 a month. Firms with a hard data-residency mandate run Cloud, our enterprise tier, inside their own network.

Regulatory coverage

Built for the rules you answer to

PrivacyPal ships detectors for every class of data these rules govern: taxpayer identity, SSNs and ITINs, EINs, bank and routing numbers, wage and K-1 detail, and the workpapers behind them. Map once, enforce everywhere, on every device your people use.

Section 7216 Section 6713 FTC Safeguards Rule IRS Pub 4557 · WISP AICPA confidentiality Circular 230
For accounting

Be the firm clients trust with the AI too

Twenty minutes, one real return, the audit log open the whole way through.