GoRefer Trust Center
AI Security & Governance
Updated September 2026
GoRefer's AI assistant, Gio, operates under a strict data governance framework designed specifically for the tax industry. This page describes what data Gio can access, how it stays within your firm, and the controls meant to reduce the risk of data exposure.
We understand that using AI in a tax workflow requires a higher bar of trust. The details below are written for both technical reviewers and non-technical firm owners.
Our policy on model training
GoRefer does not use customer inputs to train or fine-tune models. Gio sends context to Microsoft AI services to generate responses; client names, narrative and document content may be processed there. The sub-processor register lists these providers, and you can request the provider terms that apply.
What Is Gio?
Updated September 2026
Gio is GoRefer's built-in AI assistant. It can draft communications, surface referral insights, summarize client activity, suggest commission structures, and help preparers manage their workload. Gio is deeply integrated with firm data — which is why its data access is tightly controlled.
What Gio Can Do
Draft client-facing emails and referral communications
Summarize referral pipeline and commission trends
Answer questions about firm data (scoped to your firm only)
Suggest workflow improvements based on aggregated activity
Assist with document drafting and compliance checklists
Review AI drafts before relying on them; whether an action can be undone depends on the action
What Gio Cannot Do
Guarantee detection of every identifier embedded in free-form input
Read data belonging to a different firm
Independently guarantee that prior conversation context has been deleted
Replace the preparer's review and professional judgment
Control how a firm shares or uses generated output
Initiate outbound communication on your behalf without explicit approval
What Data Is Sent to AI Infrastructure?
Updated September 2026
The table below documents each data category that Gio may encounter and the protection measures applied before any data leaves GoRefer's own infrastructure.
| Data Type | Sent to AI? | How It's Protected | Sensitivity |
|---|---|---|---|
Uploaded tax documents | Yes — document recognition | The document-recognition service receives the uploaded file, including any identifiers present in it, over an encrypted connection. This is separate from the identifier filtering applied to case details. | Critical |
Client SSN / ITIN / EIN / bank and routing numbers | Filtered in case context | Left out when the client profile and intake answers are put together, and redacted from any free text — notes, document text, memo bodies — before the AI request is built | Critical |
Client name | Yes — in case and client context | Case context can include the taxpayer’s name under the requesting firm’s access controls. It is not anonymized; treat that name as visible to the AI provider. | Controlled |
Referral workflow data | Yes — in structured context | Built only from the requesting firm's records that the user is authorized to see. Public features and GoRefer's operator tools have their own context and permissions. | Standard |
Commission calculations | Yes — workflow context | Firm and preparer context can include names and related records. Do not assume all financial context is anonymous. | Standard |
Analytics & usage patterns | Yes — workflow-dependent | Some requests use firm-wide totals; some client, preparer and case features can include details about individuals. | Low |
AI Security Controls
Updated September 2026
Every AI interaction on the GoRefer platform is governed by the following technical and policy controls. The status column shows whether each one is a working control, a policy commitment or still open; open items are listed rather than left off the page.
| Control | Description | Status |
|---|---|---|
Firm isolation | Firm AI features only query that firm's data and check the user's authorization. Public features and GoRefer's operator tools have separate context and permissions. | Enforced |
No model training on customer data | GoRefer policy prohibits using customer inputs to train or fine-tune models. How the provider handles data is governed by the applicable Microsoft service terms and our configuration. | Policy |
Identifier filtering in case context | When Gio assembles a case for the AI, it leaves out supported identifier fields and redacts identifier patterns from free text. This does not cover every input to every AI feature, or the original files sent for document recognition. Client names may remain. | Enforced |
AI response audit log | Gio stores conversation content and workflow records, as well as audit metadata. Case-linked records are currently removed by an automatic cleanup 90 days after the case is created. | Enforced |
AI disclosure on preparer-facing outputs | Every Gio surface a preparer reads — chat, case chat, tax research, 1040 return review, IRS notice analysis and drafted responses, memos, review queues, due-diligence output and content drafts — carries a standing, non-dismissible notice that the output is AI-assisted and must be reviewed and verified before it is relied on. | Enforced |
AI disclosure on client-facing AI | The AI surfaces a taxpayer or website visitor interacts with directly — the embeddable Gio chat widget and the conversational client intake among them — do not yet carry a taxpayer-worded version of that notice. We have not yet decided whether one is required or how it should be worded, so this control is still open. | Open |
Professional review before reliance | AI outputs are presented as drafts. Conversation messages and generated work can be saved as part of the workflow. Preparers remain responsible for reviewing AI output before using it in client work. | User responsibility |
Fallback infrastructure | Gio uses Microsoft Foundry, with Azure OpenAI as a fallback; both run on Microsoft infrastructure. How long Microsoft keeps data depends on the applicable service terms and our configuration. | Enforced |
Prompt-injection risk controls | Input handling, structured context and prompt instructions reduce prompt-injection risk. These measures do not guarantee that every malicious instruction is detected or blocked. | Enforced |
AI Credit System as a Governance Mechanism
Updated September 2026
GoRefer's AI credit system is not just a billing mechanism — it serves as a natural rate-limiting and auditability layer. Metered Gio operations record credit usage. A billing record is not a complete audit of every data access or AI interaction.
Rate Limiting
Metered operations check available credits alongside their access controls
Administrators can review credit usage for unexpected activity
Admins can set per-user AI credit limits
Usage records
Metered operations record usage details for the applicable action
Credit history supports usage review; it is not a tamper-proof event archive
Credit history is recorded separately from case-content retention
Access Control
Credit allocations are scoped per user role
Authorized administrators can manage supported user access and limits
AI features follow the same RBAC as the rest of the platform
AI Infrastructure Isolation
Updated September 2026
How long providers keep data depends on the service
How Microsoft processes, stores and retains data depends on the service, our configuration and the applicable terms. GoRefer also stores conversation and case records. Not every request uses a zero-retention service; ask us for the current provider setup.
Request Lifecycle
Context is put together on GoRefer's own systems
Supported identifiers are filtered out of case details. Other inputs, including original documents, are processed separately; names and narrative can remain.
Requests and conversations
Gio can carry a conversation across requests, using conversations kept with the AI provider where set up and messages stored by GoRefer
Response handling
Each feature handles structured answers and AI refusals in its own way; professional review is still required
No cross-firm context
The context sent with each request comes only from the requesting firm
Failure & Fallback Handling
Primary and fallback providers
Supported features can fall back from Microsoft Foundry to Azure OpenAI; terms and retention for each service are available on request
When a provider fails
Gio shows an unavailable or error message. Conversation and case records already stored follow their own retention schedule
Incident logging
Failure logging varies by feature; details of logging and data filtering are available on request
Prompt Injection Protection
Updated September 2026
Prompt injection is a class of attack where malicious input attempts to override AI instructions, extract data from the AI context, or cause unintended behavior. GoRefer applies multiple layers of defense against these attacks.
Input Defense
User inputs are sanitized before inclusion in AI prompts
Input structure and prompt instructions reduce risk; they do not guarantee injection detection
Text from clients is kept separate from Gio's own instructions
Request-size and field-length limits depend on the feature
Output Defense
Features that need structured answers validate them
There is no universal filter that blocks personal data in AI responses
Rendering and sanitization controls reduce risk on supported screens
Independent prompt-injection testing is a goal; ask us for the scope and results of any completed test