Encryption
Protected at rest and in transit
Full-disk encryption protects stored information. TLS protects supported connections between approved users and the system.
Security & compliance
Your AI runs in your environment, with controls your firm can inspect, document, and govern.
The data boundary
For an on-premises PrivateStride deployment, approved AI workloads are processed on dedicated hardware installed in your environment.
Inside your environment
Prompts and customer content are not sent to public AI model APIs for inference. Your deployment plan documents the exact data flows, update channels, logging, backups, and support access that apply to your firm.
A governed path
Public model APIs are not part of the inference path, and your firm’s content is not used to train a shared model.
Controls
The control set is designed around the way accounting firms already manage sensitive client information.
Encryption
Full-disk encryption protects stored information. TLS protects supported connections between approved users and the system.
Access
Access is mapped to approved user groups so partners, managers, and staff can be given the permissions their work requires.
Evidence
Query and administrative activity is logged according to the retention settings agreed for your deployment.
Boundaries
Network access is limited to the paths the deployment needs, including controlled channels for approved updates.
Support
Remote support is enabled only under the access process agreed with your firm. Support activity is attributable and logged.
Review
Outputs are drafts. Your professionals review the work and remain responsible for tax positions, advice, and client communications.
Regulatory support
Private infrastructure can reduce unnecessary external data flows. It does not replace your firm’s legal, professional, or security responsibilities.
FTC Safeguards Rule
The Safeguards Rule requires covered financial institutions, including many tax preparation firms, to maintain an information security program with administrative, technical, and physical safeguards. PrivateStride provides documentation about the AI system and its controls, then works with your designated security lead so your firm can decide how to incorporate the deployment into its written information security plan.
IRC Section 7216
Section 7216 and its regulations govern certain uses and disclosures of tax return information by tax return preparers. An on-premises architecture can reduce external data flows, but location alone does not determine compliance. Your firm remains responsible for evaluating intended uses, disclosures, consents, and contractual arrangements with its advisers.
Sources: the FTC’s official Safeguards Rule guidance and the IRS Section 7216 Information Center. PrivateStride provides technical and implementation support, not legal advice or a certification of compliance.
A usable policy
When approved tools do not fit the work, people may turn to unapproved services. PrivateStride gives your team a governed path for AI-assisted work inside your environment, with access controls and activity records your firm can manage.
The goal is simple: make the approved way useful enough that your people do not need a workaround.
Capacity & AI risk assessment
Thirty minutes. We map where capacity is leaking and where unmanaged AI risk may sit. You leave with the findings whether you hire us or not.