Security and §7216

Security, data flow, and §7216 review

Every workflow is documented in terms of systems, providers, data movement, retention, permissions, and support access. That gives your firm and counsel a concrete architecture to review.

In summary

  • Data flows are documented before production use.
  • External providers are identified explicitly.
  • Access is scoped and client-revocable where supported.
  • Failed or uncertain processing is routed for review.
  • Retention and provider terms are reviewed as part of deployment planning.
  • Gulf & Ponte does not provide legal, tax, accounting, or §7216 opinions.

Deployment principles

These are the principles we design toward. Which of them a given deployment can actually implement depends on what your systems and providers support, and that is established during scoping rather than assumed here.

  • Prefer client-controlled or client-contracted infrastructure.
  • Minimize unnecessary data movement.
  • Identify external providers.
  • Use named, least-privilege, revocable access where supported.
  • Make uncertain processing visible for review.
  • Document pause, shutdown, and offboarding paths.
  • Have the firm and its counsel make legal determinations.

Example data flow

One common shape, drawn so the trust boundaries are visible. The final data flow depends on your systems, and is documented before production use.

Example data flow and trust boundaries Three separate zones. The first, drawn with a solid boundary and labelled "Your firm's environment and accounts", contains document sources such as the portal, email and upload routes; the workflow and orchestration layer; a human review queue; and the workpaper destination. The second zone, drawn outside that boundary and labelled "External providers contracted by your firm", contains the model and extraction provider; documents and extracted fields cross the boundary in both directions, and the provider processes that information under its own contractual terms. The third zone, also outside the boundary and labelled "Gulf and Ponte, scoped implementation and support access", carries workflow configuration into the firm's environment, and is marked as access that may reach information processed by the workflow. The final data flow depends on the firm's systems. YOUR FIRM’S ENVIRONMENT AND ACCOUNTS Document sources portal · email · upload Workflow and orchestration Review queue a person decides Workpaper destination EXTERNAL PROVIDERS CONTRACTED BY YOUR FIRM Model / extraction provider processes under its own terms Your account or key does not stop this being a third party. document content extracted fields GULF & PONTE — SCOPED ACCESS Implementation and support named · least-privilege · revocable Support access may reach information the workflow processes. configuration and support

The detail behind each principle

Identity and access

Workflows run under identities your firm can see, audit, and revoke. Where your identity provider supports it, that means named service identities with scoped roles rather than a shared login, secrets held in a managed secret store rather than in configuration files, and a documented rotation path.

  • Access is requested for named individuals, not shared accounts.
  • Scope is the minimum the build or support task requires.
  • Access is granted by your firm and revocable by your firm.
  • Where your systems support it, access is time-limited and logged.
  • The access inventory is a pilot deliverable, so what exists is written down.
Data storage and retention

Retention is a setting, and settings are documented rather than assumed. For each system and provider in the workflow we record where data comes to rest, how long it stays, what deletion is available, and who can trigger it.

Where a provider’s default retention conflicts with your firm’s policy, that conflict is surfaced during scoping rather than after go-live.

External providers

The workflow is designed to run in infrastructure controlled or contracted by your firm when the chosen architecture supports that. Gulf & Ponte does not operate a separate production document store for the standard in-environment deployment.

A client-owned account or API key does not mean no third party processes data. External model, cloud, portal, email, and software providers may process information under their own contractual terms. Training opt-out, retention controls, and enterprise terms are data-governance controls, not legal conclusions.

  • Your firm may contract directly with cloud, portal, model, email, and software providers.
  • Whether an entity is legally a contractor, processor, subprocessor, or permitted recipient depends on the facts and on legal analysis.
  • Gulf & Ponte documents the technical relationship. We do not make the legal determination.
  • Any service contracted directly by Gulf & Ponte is disclosed and approved before it processes client data.
Logging and auditability

Production actions are traceable: what ran, when, against which document, under which identity, and what the outcome was. Failures are logged as failures rather than swallowed.

Uncertain or failed processing goes to a review queue instead of proceeding. During a pilot, no final filing happens without the agreed human review step.

Support access

Scoped implementation or support access may allow Gulf & Ponte to encounter information processed by the workflow. The access model is therefore documented, and should be named, least-privilege, logged, revocable, and time-limited where the client’s systems support those controls.

We will not claim to be blind to your data. Whether support access can reach taxpayer return information is a question about the specific systems and permissions involved, and it is answered in the access documentation rather than in a marketing sentence.

Continuity

Gulf & Ponte is a one-person practice, which is a genuine key-person risk. Each engagement defines the operating documentation, access model, handoff, and transition terms appropriate to the workflow.

  • Standard: production accounts under your control, a documented deployment and data flow, a runbook, an access inventory, and shutdown instructions.
  • Contractual: repository ownership, source-code access, infrastructure-as-code delivery, transition support, and emergency access arrangements, each settled in the statement of work.
  • Determined during scoping: whether configuration can be exported from the systems in scope, which continuity controls your providers support, and who holds the credentials of record.

A runbook reduces dependency but does not eliminate key-person risk. Until the contractual controls are agreed in a statement of work, they are available terms rather than things you have.

§7216 review considerations

Section 7216 treatment is fact-specific. Relevant questions may include what information is transmitted, who receives or can access it, the purpose of the processing, provider location, contractual restrictions, retention, and whether consent or another permitted basis applies. Gulf & Ponte documents the technical facts for review; your firm and counsel make the legal determination. [ Internal Revenue Service Source: Section 7216 information center — Internal Revenue Service, Current guidance. ; Electronic Code of Federal Regulations Source: 26 CFR § 301.7216-1 — Penalty for disclosure or use of tax return information — Electronic Code of Federal Regulations, Current text. ]

Where a data flow raises a potential consent question, Gulf & Ponte flags it for review by your firm and counsel, and points to the current IRS guidance on consent format and content. Any sample or template language is a starting point for your counsel, not legal advice, and not a determination that consent is or is not required. [ Electronic Code of Federal Regulations Source: 26 CFR § 301.7216-3 — Disclosure or use permitted only with the taxpayer’s consent — Electronic Code of Federal Regulations, Current text. ; Internal Revenue Service Source: Rev. Proc. 2013-14 — format and content of taxpayer consents under § 301.7216-3 — Internal Revenue Service, Modifies and supersedes Rev. Proc. 2008-35. ]

Primary references and professional guidance

Primary references

Professional guidance

The following are professional guidance from accounting bodies and press, not law. They are useful orientation for a discussion with counsel and should not be relied on as the basis for a determination.

Security review checklist

These are the controls and questions we work through during scoping. They are not certifications, and nothing on this list is a claim that a control is already in place for your deployment.

Data protection

  • Encryption in transit
  • Encryption at rest
  • Data residency
  • Retention and deletion

Identity and access

  • Identity provider
  • Multi-factor authentication
  • Role-based access
  • Secrets storage
  • Key rotation
  • Support access approval

Operations

  • Audit logs
  • Backup and recovery
  • Incident response contacts
  • Dependency management
  • Business continuity

Contractual

  • Provider terms
  • Training and data-use settings
  • Client offboarding
  • Code and infrastructure ownership

What we do not claim

  • Gulf & Ponte does not currently hold a SOC 2 report or security certification.
  • We do not provide a §7216 legal opinion.
  • We do not claim a legal classification for ourselves or for any provider.
  • We do not prepare, review, or sign returns.

Gulf & Ponte provides technical implementation information, not legal advice. Your firm and its counsel are responsible for determining the requirements that apply to each workflow.