Every provider's website says the same thing: enterprise-grade, bank-level, military-strength security. None of those phrases are auditable. SOC 2 is — which is why it has become the de facto trust standard for firms placing client tax data with a service provider.
What SOC 2 Actually Is
A SOC 2 examination is an independent CPA-firm audit of a service organization's controls against the AICPA Trust Services Criteria — security, and optionally availability, processing integrity, confidentiality, and privacy. The output is a detailed report describing the provider's systems, its controls, and the auditor's testing of them.
Type I vs Type II — the Distinction That Matters
- Type I: controls are suitably designed as of a point in time — a snapshot
- Type II: controls operated effectively over a period (typically 6–12 months) — the auditor tested them in action
Type II is the meaningful bar for an ongoing preparation relationship. A Type I is a reasonable starting point for a newer provider, with Type II on a stated timeline.
How to Read the Report (in 20 Minutes)
- Scope: does the audited system actually include the preparation environment your returns will run through — or just the corporate website?
- Trust criteria covered: security at minimum; confidentiality is highly relevant for tax data
- Exceptions: auditor-noted control failures, and management's responses — a few minor exceptions with credible remediation beats a suspiciously spotless report
- Subservice organizations: which dependencies (cloud hosting, etc.) are carved out, and how they're monitored
- Complementary user controls: the items your firm must handle (MFA on your side, access reviews) — these belong in your WISP
SOC 2 Is Necessary, Not Sufficient
The report evidences infrastructure discipline. It does not tell you whether preparers understand S-corp basis, whether 7216 consents are handled correctly, or whether the same team returns each season. Pair the SOC 2 review with tax-specific diligence: security walkthrough, sample workpapers, references from firms your size.
Where GTPH Stands
GTPH's preparation environments run on independently audited controls with no-local-storage policies, monitored access, and confidentiality binding every team member — and we provide our security documentation package during evaluation, not after signature. Ask for it; providers who hesitate are answering your question a different way.
