Security
Tax CRM security built around
controlled access
Tax-resolution firms work with transcripts, Forms 2848 and 8821, financial statements, notices, client communications, and payment information. TaxRes CRM is designed to keep that work inside controlled client and case records instead of spreading it across email inboxes, personal calendars, spreadsheets, and unrelated applications.
Built by a practicing tax-resolution professional. Refined every day through real client work.
One client file, with access controlled by role
TaxRes CRM organizes documents, communications, tasks, tax records, and case activity inside the client file. Role-based permissions let a firm control which areas employees can access based on their work. A case manager does not need the same access as a billing administrator. A document specialist does not need the same permissions as a firm owner. Access should match responsibility.
Database-enforced office boundaries
TaxRes CRM uses tenant-aware database policies, including Row Level Security, to scope authenticated access to the correct office and user context instead of relying only on interface filtering.
Sensitive documents are not public assets
Document storage is designed around private buckets and controlled access patterns so taxpayer files are not exposed through permanent public URLs.
Service credentials stay server-side
Privileged service roles and provider secrets are separated from normal browser access and are not intended to be exposed in client-side settings or marketing code.
Encrypted connections
Public product traffic is served over HTTPS and protected in transit using modern TLS through the hosting and platform providers used by TaxRes CRM.
Control who can see and do what
Assign access according to role and responsibility. Limit sensitive areas to the staff members who need them for their work.
Keep taxpayer documents out of ordinary email
Clients can upload documents through a client-facing portal. Staff can organize documents inside the client record instead of relying on scattered attachments and local folders.
Record activity inside the case
Case notes, communications, tasks, document activity, and other records remain connected to the client or matter. Audit visibility helps a firm review what occurred and when.
Public links do not expose the staff CRM
Scheduling, document signing, intake, and client-facing pages use dedicated public experiences. Staff access remains separate from public website access.
Access should end when employment ends
Invites, role changes, password recovery and deactivation use authenticated account flows. Firms should remove access promptly when a staff member no longer needs taxpayer information.
Backup and recovery are operational controls
TaxRes CRM uses managed database and infrastructure services that provide recovery capabilities. Product recovery procedures and retention settings are operational controls that should be reviewed for the specific production configuration being used.
Know what happens when a firm leaves
Customers may request access, correction, export or deletion of account data subject to contractual, legal, operational and record-retention requirements.
Authentication controls should match the risk
TaxRes CRM uses managed authentication and controlled session flows. We do not claim multi-factor authentication is mandatory unless it is actually enforced for the account configuration being sold.
What a tax firm should ask
Security questions worth asking before you move taxpayer data.
Can another office query my records?
Tenant isolation should exist at the database layer, not only in the interface.
Are client documents public?
Sensitive files should use private storage and controlled access instead of permanent public links.
Who can change access?
Owners and administrators should be able to assign roles, remove access, and review sensitive changes.
What certifications are verified?
TaxRes CRM does not advertise SOC 2, ISO 27001 or other certifications unless independently verified.
Security Architecture
Controls a tax-resolution firm should be able to ask about.
TaxRes CRM uses multiple layers of access control rather than depending on a single login screen or hidden navigation item.
Database-level access boundaries
Authenticated access is scoped to the correct firm using database-level Row Level Security policies, reducing reliance on application filtering alone.
Sensitive files are not ordinary public assets
Protected documents use private storage and controlled signed-access patterns where file confidentiality is required.
Encrypted application traffic
TaxRes CRM is served over HTTPS/TLS. Managed infrastructure also provides encryption controls for stored application data.
Service credentials stay server-side
Privileged service roles and provider credentials are separated from ordinary browser sessions and end-user permissions.
Session and recovery controls
Authenticated sessions, password-reset flows, access removal and role changes are handled through controlled account workflows.
Sensitive activity can be reviewed
Audit-oriented records are maintained for sensitive administrative and application events where the workflow requires reviewability.
TaxRes CRM does not claim SOC 2, ISO 27001, PCI, HIPAA or another independent certification unless that certification has been verified for the applicable product and scope. We prefer to demonstrate implemented controls during a security walkthrough.
Security is also an operating process
Software controls matter, but firm procedures matter too. TaxRes CRM should be used alongside documented internal practices for staff onboarding and termination, password management, device security, access reviews, client identity verification, record retention, incident reporting, vendor review, and staff training.
A CRM can organize and restrict access. It cannot replace the professional responsibilities of the firm using it.
Shared responsibility
TaxRes CRM is responsible for maintaining the application and the controls provided by the platform. Each subscribing firm remains responsible for:
- Deciding which employees receive access.
- Assigning appropriate roles.
- Removing access when a staff member leaves.
- Protecting login credentials.
- Securing employee devices and email accounts.
- Reviewing client and taxpayer information before it is uploaded.
- Following applicable professional, legal, and regulatory obligations.
- Configuring third-party services connected to the CRM.
Security is strongest when the software and the firm's internal procedures support each other.
Public website data
The public marketing website is not intended for taxpayer records. Do not submit Social Security numbers, Employer Identification Numbers, tax returns, IRS transcripts, bank statements, forms containing taxpayer identification numbers, account credentials, or unredacted client documents. Use the approved client portal or another authorized secure method for sensitive records.
Screenshots and demonstration data
TaxRes CRM marketing screenshots and demonstrations use fictional information. The website does not use real taxpayer names, Social Security numbers, addresses, transcripts, or notices in product examples. This applies to homepage screenshots, feature pages, demonstrations, training materials, resource articles, and social-media posts.
Third-party services
Some TaxRes CRM functions may rely on third-party providers for communications, payments, accounting connections, hosting, or email. A connected service may have its own security controls, privacy policy, terms, data-retention practices, and authentication requirements. Firms should review third-party services as part of their own vendor-management process.
Questions to ask during your demonstration
During a live walkthrough, firms may ask to see how roles and permissions are assigned, how public client pages differ from staff access, where uploaded documents appear, how calls, email, and SMS connect to a client file, how completed e-signatures return to the record, how access is removed for an employee, and how case activity is recorded.
We would rather show the control than make a broad claim about it.
Report a security concern
To report a suspected vulnerability or security issue, email: info@taxrescrm.net with the subject line "Security Report — TaxRes CRM." Include a clear description of the issue, the page or feature affected, steps needed to reproduce it, and your contact information. Do not include taxpayer data in any report. Do not publish a suspected vulnerability before TaxRes CRM has had a reasonable opportunity to review it.
Get Started
See how access, documents, and client records work together
The demonstration uses fictional case data and shows the product from both the firm and client sides.
Book a DemoLive walkthrough with the builder — a practicing tax resolution professional, not a sales rep.