A six-person tax practice or a 300-person firm: same install, same afternoon. PrivacyPal is the on-device governance layer that lets preparers, bookkeepers, auditors and advisory staff use ChatGPT, Claude, Copilot, Gemini, Grok and Perplexity on live client work. Taxpayer names, SSNs, EINs, account numbers and wage detail are swapped before anything leaves the device. Section 7216, the FTC Safeguards Rule and AICPA confidentiality stop being the reason your firm says no to AI.
Section 7216 makes it a criminal matter for a return preparer to disclose or use tax return information without the taxpayer's written consent. A staff accountant dropping a K-1 into a public chatbot is a disclosure: a misdemeanor carrying up to $1,000 and a year, plus $250 per disclosure under Section 6713. The AICPA's Confidential Client Information Rule says the same thing in professional terms, and the FTC Safeguards Rule already requires a written plan naming who may touch client data and where it goes.
Nobody in your firm is trying to breach any of that. They are trying to finish a return at 9pm in March. PrivacyPal makes the compliant path the default path: staff keep the AI, client identity never crosses the perimeter, and every prompt lands in a log your peer reviewer, your insurer and your clients can be shown.
10 swaps in one prompt: names, SSN, EIN, entity, address, amounts · answer comes back with the real values restored · no Section 7216 disclosure occurs · every touch logged
Run AI over real 1040s, 1120s and K-1s. Taxpayer names, SSNs, ITINs, EINs and addresses are swapped before the model reads a single line.
Month-end close, reconciliations, cleanup work. Vendor names, payroll detail and bank account numbers stay inside the practice.
Model entity structures, distributions and planning scenarios on the client's real numbers. Turn financial twins off and the math stays exact while identity stays protected.
Summarize workpapers, draft testing memos, interrogate a trial balance. Client identity and non-public results never reach an outside model.
Blue J, TaxGPT and the rest are good at the job they were built for: a research question, a citation, a memo. Then a preparer opens Claude to rewrite a client email with the client's numbers still in it. An admin drops a scanned W-2 into ChatGPT to pull the figures out. A partner runs Perplexity over a prospect. Someone points an agent at the engagement folder and walks away. That is where firm data actually goes, and no tax-specific tool is watching any of it.
PrivacyPal does not replace those tools. It governs everything around them, so the AI your people reach for at 9pm is held to the same policy as the AI your firm formally approved.
ChatGPT, Claude, Gemini, Copilot, Grok and Perplexity, intercepted on the device before a prompt leaves it. When the firm adopts the next one, the policy does not have to be rewritten.
Claude Code, Copilot agents, Hermes Agent and Private MCP run under the same firm policy. What an agent may read, write and send out is a setting, not a hope. Max only.
On-device DSPM and shadow AI discovery surface the tools your staff signed up for on their own, while there is still time to do something about it.
Client PII is the obvious asset. It is not the only one. The firm's real property is the work product: the tax strategies refined over twenty years, the engagement templates, the pricing model, the client list, the workpaper methodology nobody else has. All of it sits in a system of record, the general ledger, the practice management system, the tax software, the client portal, and all of it is one automation away from being pasted into somebody's model.
PrivacyPal is the only governance layer that protects the firm's own intellectual property at the same moment it protects the client's identity, on the device, before either one leaves. Connect the systems of record and the data stays in them.
PrivacyPal learns what is sensitive at the source, so it is recognized the moment it surfaces in any AI, in a prompt, a paste or an agent's tool call. Salesforce, Slack, Workday, Oracle ERP and financials, Notion, Google Drive, SQL, Google Docs and Word ship today.
The sanctioned route for an agent to reach an internal system without that connection leaking to a public host. The model works on twins, the system of record sends and receives real values, your people see the real answer. NetSuite, Intuit and your practice management stack connect this way: build it with @privacypal/private-mcp or with us.
The exported trial balance, the downloaded return, the client file somebody saved to the desktop in February. Classified where it sits, on staff laptops, before any model gets near it.
One policy from the ledger to the prompt · systems of record keep their data · agents get the context, never the underlying values
Most firms wrote the memo, circulated the acknowledgement form and moved on. A signed form tells you what staff agreed to. It does not tell you what they pasted.
| Approach | Productivity | Client data exposure | Evidence for review |
|---|---|---|---|
| Ban AI in the practice | Near zero. Staff use it on their phones. | Unknown: no visibility | No |
| Signed AI policy on file | Unchanged. The judgment call sits with each preparer. | One paste away, every time | A signature, not a log |
| PrivacyPal | Every tool, every preparer | Zero: swapped before send | Per-prompt, exportable, SIEM-ready |
Between January and April the firm is a different firm: seasonal preparers, contract reviewers, an offshore team carrying the volume overnight. Every one of them is a disclosure decision under Section 7216 and a third-party service provider question under the AICPA rules.
PrivacyPal Max attaches to the firm domain and provisions each of those seats centrally, on whichever device and in whichever country it sits. Onboard in October, deprovision in May, and hold the identical policy for a partner in the office and a preparer eight time zones away. Nobody has to remember the rule, because the rule is enforced at the device.
Dollar amounts are twinned by default. Switch financial twins off in Settings and money values pass through untouched, so a strategy calculation stays exact. Names, SSNs, EINs, account numbers and dates keep full protection either way. Per user, not per firm.
Every prompt, every file, every AI surface, logged with who touched what and from which device. Export it into the written information security plan the Safeguards Rule already requires of you.
Mac, Windows and the browser, governed the same way. The home PC a preparer uses in March and the office laptop they use in June are one seat, one policy, one audit trail.
Max covers everyone who touches a client file: attach the firm domain, provision partners, preparers, bookkeepers and seasonal staff centrally, and hold one confidentiality policy across every service line. $30 per seat a month at 1 to 9 seats, $25 at 10, $21 at 100, billed annually. A sole practitioner covering only themselves runs Pro at $7.50 a month. Firms with a hard data-residency mandate run Cloud, our enterprise tier, inside their own network.
PrivacyPal ships detectors for every class of data these rules govern: taxpayer identity, SSNs and ITINs, EINs, bank and routing numbers, wage and K-1 detail, and the workpapers behind them. Map once, enforce everywhere, on every device your people use.