Every paid tax preparer, from a solo bookkeeper to a 500-person CPA firm, is federally regulated as a financial institution under the FTC Safeguards Rule. The IRS logged nearly 300 tax-pro breaches in the first half of 2025 alone. If you built a client portal or intake form with Lovable, Base44, or Replit, you sit at the intersection of both trends — and the platform isn't the regulated party. You are.
Free Accounting App Scan → Talk to UsClient portals, tax-organizer forms, and bookkeeping dashboards all touch SSNs, bank data, and full tax files. Here is where AI-built firm apps create GLBA and IRS exposure.
A tax file is the richest identity-theft artifact there is: SSNs for the client, spouse, and dependents, income, employer, bank routing and account numbers for refunds, and prior-year AGI, which the IRS itself uses as an authentication factor. One breached intake table enables fraudulent-return filing at scale.
The IRS logged roughly 300 tax-pro breaches in the first half of 2025 alone, affecting up to 250,000 clients. A breach triggers simultaneous duties: FTC notification within 30 days, the IRS Stakeholder Liaison "immediately," state notification, and client notification — and plaintiff firms have filed class actions within days of disclosure.
Criminals routinely pose as prospective clients and send fake "tax documents" designed to harvest credentials, a threat serious enough that the IRS ran a dedicated "Protect Your Clients" campaign in 2026. An AI-built intake form that accepts arbitrary uploads from unvetted "new clients" industrializes this exact attack.
A stolen EFIN lets criminals e-file fraudulent returns that appear to come from your legitimate firm. If those credentials end up in an AI app's environment variables or client-side code — a common vibe-coding mistake — you can lose the exact credential your e-file business depends on.
The FTC Safeguards Rule requires MFA, encryption, and access controls. AI platform failures map onto these one-to-one: Base44's 2025 auth bypass defeated MFA and SSO entirely, and Lovable's CVE-2025-48757 left access control absent through missing row-level security in 170+ apps. The firm, not the platform, is the regulated financial institution.
Every preparer already attested on IRS Form W-12, under penalty of perjury, that they understand the data-security-plan obligation. After a breach, "we didn't know" is off the table — the firm signed that it knew before it ever built the app.
| What you built | Hidden risk |
|---|---|
| Client portal / document exchange | Auth that looks finished but isn't; makes you an IRS "Online Provider" with TLS + weekly scan duties |
| Tax-organizer / document-upload intake | Exposed database — an intake table is literally names, SSNs, and income |
| Invoicing / billing app | Payment data + client PII can fall under state privacy laws outside the GLBA exemption |
| Bookkeeping dashboard (bank-feed summaries) | AI agents with production-DB access; hard-coded bank credentials client-side |
| Client-facing AI chat / tax-answer bot | Disclosing return info beyond prep without consent is penalized per disclosure, no intent required |
| E-signature / engagement-letter tool | Unencrypted transmission of return data violates the firm's own written security plan |
| Regulation | Triggers when… | Penalty |
|---|---|---|
| FTC Safeguards Rule (GLBA) | Automatically — tax preparers are named financial institutions, no minimum size | Up to per violation; each missing safeguard counted separately |
| IRS WISP mandate | All paid preparers, any size — a written data security plan is federal law | FTC enforcement + IRS Stakeholder Liaison + state reporting |
| FTC breach notification (314.5) | Unauthorized acquisition of unencrypted info of 500+ consumers | Notify FTC within 30 days; published in a public database |
| IRC §7216 (criminal) | Knowing or reckless disclosure of return info without consent | Up to /violation ( if identity-theft-connected) + up to 1 year |
| IRC §6713 (civil) | Any unauthorized disclosure or use — no intent required | per disclosure, up to /yr |
| IRS e-file Publication 1345 | Online Providers collecting data via a website | Sanctions up to suspension or expulsion from IRS e-file |
Yes, regardless of size. The FTC Safeguards Rule names tax preparers as financial institutions with no minimum threshold, and the IRS states plainly that a written data security plan is federal law, not optional guidance, for every paid preparer.
It's a GLBA-based rule requiring a qualified individual, risk assessment, access controls, encryption, MFA, and an incident-response plan. It applies automatically to any paid tax or accounting preparer; violations run up to each, with every missing safeguard counted separately.
Not by default. Lovable's CVE-2025-48757 exposed 170+ apps through missing database access controls, and Base44 had a critical authentication bypass in 2025. Neither platform being the regulated party removes your firm's Safeguards Rule liability if client data leaks.
You must notify the FTC within 30 days if 500 or more consumers are affected, notify your IRS Stakeholder Liaison immediately, and meet state notification duties. Real breaches have drawn class actions within days, so having an incident-response plan ready matters as much as prevention.
Yes. IRS guidance (IR-2024-201) requires MFA for anyone accessing any system holding taxpayer information, regardless of firm size, and disabling MFA in tax software is itself a Safeguards Rule violation under 16 CFR 314.4(c)(5).
We check MFA and access controls against Safeguards Rule requirements, database encryption and row-level security on client portals, whether EFIN or API credentials are exposed in code, and IRS Publication 1345 compliance if you collect data through a website. You get a plain-English report ranked by risk.
Get a free, no-obligation scan of your firm's app — Safeguards Rule gaps, database access, and credential exposure, in plain English.
Start With a Free Scan →