Skip to main content
Accounting & Tax

Client Tax Data Stays on Your
Firm's Machines.

CPAs, tax preparers, and auditors are using ChatGPT, Claude, and Copilot every day, pasting client SSNs, W-2s, bank account numbers, and tax returns into prompts. Shield sits on your firm's machines and stops client financial data from ever reaching an external AI model. No cloud. No vendor access. Just a local proxy that redacts sensitive data before it leaves your network.

See Shield for AccountingSee Data Redaction in Action
Quick Answer

Shield for Accounting & Tax is a local desktop application that stops client tax returns, SSNs, EINs, bank account numbers, and confidential financial data from ever leaving your firm's computers, before that data reaches ChatGPT, Claude, Copilot, or any AI model. It runs on your existing machines, requires no cloud infrastructure, and helps CPA firms meet IRS Pub 1075, GLBA Safeguards Rule, and AICPA confidentiality requirements without changing how tax preparers, auditors, and advisors use AI tools.

IRS Pub 1075
Federal Tax Information security requirements

IRS Publication 1075 requires agencies and authorized recipients of federal tax information (FTI) to implement NIST 800-53 security and privacy controls, including encryption (FIPS 140-validated), access controls based on need-to-know, 24-hour incident reporting, and annual risk assessments. Unauthorized disclosure of FTI is prohibited under IRC §6103 and can result in criminal prosecution under IRC §7213.

Source: IRS Publication 1075; IRC §6103, §7213
GLBA Safeguards
FTC rule covering tax preparers as financial institutions

The FTC Safeguards Rule, issued under the Gramm-Leach-Bliley Act, defines tax preparers and CPA firms as 'financial institutions' that must protect nonpublic personal information. Requirements include a written information security program (WISP), risk assessments, encryption of customer data, multifactor authentication, activity logging and monitoring, and an incident response plan. The rule applies regardless of firm size.

Source: 16 CFR Part 314; FTC Safeguards Rule; GLBA
Zero
Client data leaves your firm's network

Shield runs locally on your firm's machines. It never transmits data to Purfect Labs servers. When a CPA pastes a tax return into ChatGPT, Shield redacts SSNs, EINs, bank accounts, and income data before the prompt leaves the machine. The AI provider never sees the original client data. The response is rehydrated locally so the CPA gets a usable answer, all within your existing IT environment, no cloud infrastructure required.

Shield architecture, local proxy, client-side redaction

Client data exposure through AI is a regulatory and professional liability risk

When a CPA pastes a client's SSN, bank account numbers, or tax return details into an AI prompt, that data leaves the firm's controlled environment and lands on an external provider's servers. Under IRS Pub 1075, the GLBA Safeguards Rule, and the AICPA Code of Professional Conduct, accounting firms have obligations to protect client financial information, and those obligations don't disappear just because a staff member is using a third-party AI tool. Shield eliminates this vector entirely: sensitive client data never leaves your network, so it never creates a compliance exposure across tax, audit, or advisory workflows.

Interactive Demo

What Client Data Looks Like in AI Prompts

Three real-world scenarios where accounting professionals send sensitive client data to AI models. Click each tab to see the raw prompt with identifiable information, and how Shield redacts it before it leaves your network.

CPA Preparing Client Tax Return with AI Assistance

A CPA uses an AI assistant to draft a complex tax position memo for a high-net-worth client, pasting the client's SSN, income data, bank account details, and prior-year return information into the prompt.

Before Shield, Raw Prompt
Draft a tax position memo for client James Whitfield, SSN 421-88-9753, PTIN P00987432, filing status: married filing jointly. 2025 income: W-2 wages $385,000 (employer EIN 87-4291104), Schedule C consulting income $142,700, capital gains $89,400 (cost basis $412,000, sale price $501,400). Deductions: mortgage interest $34,200, charitable contributions $28,500, SALT $10,000 cap. Bank account for refund direct deposit: Wells Fargo routing 121000248, account 889472610. Prior year AGI (2024): $468,200. Dependents: Sophia Whitfield (SSN 519-44-3376, age 15), Ethan Whitfield (SSN 519-44-9951, age 18, full-time college student).
After Shield, Redacted Prompt
Draft a tax position memo for client [CLIENT_NAME]], SSN [SSN]], PTIN [PTIN]], filing status: [FILING_STATUS]]. 2025 income: W-2 wages [AMOUNT]] (employer EIN [EIN]]), Schedule C consulting income [AMOUNT]], capital gains [AMOUNT]] (cost basis [AMOUNT]], sale price [AMOUNT]]). Deductions: mortgage interest [AMOUNT]], charitable contributions [AMOUNT]], SALT [AMOUNT]] cap. Bank account for refund direct deposit: [BANK_NAME]] routing [ROUTING_NUMBER]], account [ACCOUNT_NUMBER]]. Prior year AGI: [AMOUNT]]. Dependents: [DEPENDENT_NAME]] (SSN [SSN]], age [AGE]]), [DEPENDENT_NAME]] (SSN [SSN]], age [AGE]], full-time college student).
What Shield Caught, 9 Data Points Redacted
PII, NameJames Whitfield
PII, SSN421-88-9753
PII, PTINP00987432
PII, EIN87-4291104
Financial, Bank889472610
Financial, Routing121000248
PII, SSN519-44-3376
PII, SSN519-44-9951
Financial, Income$385,000

Compliance

Frameworks That Apply to AI Use in Accounting

CPA firms operate under multiple regulatory frameworks, each with data protection requirements that extend to AI tool usage. Shield helps your firm maintain compliance across them all.

Framework
What It Requires
How Shield Helps
IRS Pub 1075
Requires agencies and tax preparers receiving federal tax information (FTI) to implement NIST 800-53 security controls: encryption (FIPS 140-validated), need-to-know access, 24-hour incident reporting to TIGTA and IRS, annual risk assessments, and secure disposal of FTI.
Shield prevents FTI, SSNs, EINs, PTINs, income data, from leaving your firm's machines through AI prompts. Because Shield redacts before transmission, FTI never reaches the external AI provider, eliminating the need to report AI-prompt incidents under Pub 1075's 24-hour notification requirement.
GLBA / FTC Safeguards Rule
Tax preparers and CPA firms are 'financial institutions' under the Safeguards Rule. Requirements include a written information security program (WISP), risk assessments, encryption of customer data in transit and at rest, multifactor authentication, activity monitoring, and written incident response plans.
Shield acts as a technical safeguard that encrypts and redacts nonpublic personal information at the network edge, before it reaches any AI provider. Consistent enforcement across all staff and AI tools, supporting your WISP's technical control requirements.
AICPA Professional Standards
ET §1.700.001 requires CPAs to maintain client confidentiality. The AICPA Code of Professional Conduct applies regardless of the tools used, AI does not create an exception. State boards of accountancy may impose additional data security obligations.
Shield enforces confidentiality controls uniformly: whether a partner drafts a tax memo, an auditor reviews financial statements, or a staff accountant analyzes client data, sensitive information is always redacted before reaching external AI. Provides demonstrable evidence of confidentiality controls for peer review.
State Data Breach Laws
All 50 states require firms to notify affected individuals when unencrypted personal information, SSNs, financial account numbers, tax ID numbers, driver's license numbers, is acquired by an unauthorized person. Notification triggers vary by state but generally apply when data is accessed without authorization.
Shield prevents the data exposure that triggers notification obligations. Because client PII is redacted before transmission, no unauthorized access event occurs, removing the legal and reputational cost of breach notification entirely.
SOC 2
SOC 2 reports evaluate service organization controls across five trust service criteria: security, availability, processing integrity, confidentiality, and privacy. For CPA firms handling client data through AI tools, confidentiality and privacy criteria are directly relevant to AI usage.
Shield adds a demonstrable confidentiality control for AI workflows. When a firm undergoes a SOC 2 examination, Shield's local redaction and audit logging provide evidence that client data is protected even when staff use AI tools, supporting the confidentiality and privacy trust service criteria.

Architecture

How Shield Protects Client Data in Accounting Workflows

CPA FirmTax / Audit / Advisoryprompt + client PIIShieldLocal Redaction ProxySSNs, EINs, bank accts, incomeclean prompt onlyAI ProviderChatGPT / Claude / etc.AI responserehydrate locallyresponse with client data restoredYour Firm NetworkExternal Internet

Client data (SSNs, EINs, bank accounts, tax returns) is redacted by Shield within your firm's network. Only the cleaned prompt reaches the AI provider. Responses are rehydrated locally, the provider never sees original client data, and your firm retains full control under IRS Pub 1075, GLBA, and AICPA standards.

FAQ

Common Questions

Yes, but Shield operates at a different layer. IRS Pub 1075 requires agencies and tax preparers receiving federal tax information (FTI) to implement NIST 800-53 security controls: encryption, access controls, audit logging, and incident response within 24 hours. Shield complements your Pub 1075 program by ensuring that FTI, SSNs, EINs, PTINs, income data, bank account numbers, never leaves your firm's machines when staff use AI tools like ChatGPT, Claude, or Copilot. It's a technical safeguard that closes the accidental-disclosure vector that's hardest to control: employees copying client data into prompts.
Yes. Under the Gramm-Leach-Bliley Act (GLBA), the FTC defines tax preparers and CPA firms as 'financial institutions' because they handle nonpublic personal information. The Safeguards Rule requires these firms to develop a written information security program (WISP), conduct risk assessments, encrypt customer data in transit and at rest, implement multifactor authentication, and log and monitor for unauthorized access. When a CPA pastes a client's SSN, bank account numbers, or tax return into an AI prompt, that customer data is leaving the firm's controlled environment, potentially creating a Safeguards Rule compliance gap. Shield closes this gap at the network edge, redacting sensitive data before it reaches any external AI provider.
The AICPA Code of Professional Conduct requires CPAs to maintain client confidentiality (ET §1.700.001). This applies regardless of the tool being used. Using AI doesn't relieve a CPA of the obligation to protect client data. Additionally, the AICPA has issued guidance on using emerging technologies that emphasizes maintaining competence and due care when adopting AI tools. State boards of accountancy may also have data security requirements tied to professional licensing. Shield provides a consistent technical control that applies across all AI tools, your staff can't accidentally paste client data into the wrong prompt.
Shield helps prevent the data exposure that triggers notification obligations in the first place. All 50 states have data breach notification laws that require firms to notify affected individuals when unencrypted personal information, including SSNs, financial account numbers, and tax ID numbers, is acquired by an unauthorized person. If a CPA inadvertently sends client SSNs and bank details through an AI prompt, that may constitute a breach requiring notification under state law. Shield prevents that data from reaching the external provider, so no notification event occurs.
Shield operates at the API layer, between your AI client and the LLM provider. It doesn't need to integrate with any specific tax preparation software (UltraTax, ProSeries, Lacerte, Drake), practice management system (Canopy, Karbon, TaxDome), or document management platform. As long as the AI request flows through Shield's local proxy, client financial data is caught regardless of which system the accountant copied it from. Zero integration work required.
Shield installs on any Mac, Windows, or Linux machine. For firm-wide deployment, your IT team can push Shield via existing device management tools or group policy. Every machine gets the same policy configuration, consistent data protection across tax, audit, and advisory teams. Audit logs can be centrally collected. Shield supports enterprise configuration management so you can deploy across every partner laptop, staff workstation, and shared terminal without touching a single app.

Ready to Protect Your Clients' Data?

Shield installs in minutes. Your clients' tax returns, SSNs, bank account numbers, and confidential financial data stay on your firm's machines, where IRS Pub 1075, GLBA, and your professional standards expect them to be.

Talk to Our TeamHow Shield Works

Last updated: August 2, 2026