Skip to content

GoRefer Trust Center

AI Security & Governance

Updated September 2026

GoRefer's AI assistant, Gio, operates under a strict data governance framework designed specifically for the tax industry. This page describes what data Gio can access, how it stays within your firm, and the controls meant to reduce the risk of data exposure.

We understand that using AI in a tax workflow requires a higher bar of trust. The details below are written for both technical reviewers and non-technical firm owners.

Firm Isolated
Case-Context Identifier Filtering
No-Training Policy
AI Audit Logs
Human Review Required

Our policy on model training

GoRefer does not use customer inputs to train or fine-tune models. Gio sends context to Microsoft AI services to generate responses; client names, narrative and document content may be processed there. The sub-processor register lists these providers, and you can request the provider terms that apply.

What Is Gio?

Updated September 2026

Gio is GoRefer's built-in AI assistant. It can draft communications, surface referral insights, summarize client activity, suggest commission structures, and help preparers manage their workload. Gio is deeply integrated with firm data — which is why its data access is tightly controlled.

What Gio Can Do

  • Draft client-facing emails and referral communications

  • Summarize referral pipeline and commission trends

  • Answer questions about firm data (scoped to your firm only)

  • Suggest workflow improvements based on aggregated activity

  • Assist with document drafting and compliance checklists

  • Review AI drafts before relying on them; whether an action can be undone depends on the action

What Gio Cannot Do

  • Guarantee detection of every identifier embedded in free-form input

  • Read data belonging to a different firm

  • Independently guarantee that prior conversation context has been deleted

  • Replace the preparer's review and professional judgment

  • Control how a firm shares or uses generated output

  • Initiate outbound communication on your behalf without explicit approval

What Data Is Sent to AI Infrastructure?

Updated September 2026

The table below documents each data category that Gio may encounter and the protection measures applied before any data leaves GoRefer's own infrastructure.

Data TypeSent to AI?How It's ProtectedSensitivity
Uploaded tax documents
Yes — document recognitionThe document-recognition service receives the uploaded file, including any identifiers present in it, over an encrypted connection. This is separate from the identifier filtering applied to case details.Critical
Client SSN / ITIN / EIN / bank and routing numbers
Filtered in case contextLeft out when the client profile and intake answers are put together, and redacted from any free text — notes, document text, memo bodies — before the AI request is builtCritical
Client name
Yes — in case and client contextCase context can include the taxpayer’s name under the requesting firm’s access controls. It is not anonymized; treat that name as visible to the AI provider.Controlled
Referral workflow data
Yes — in structured contextBuilt only from the requesting firm's records that the user is authorized to see. Public features and GoRefer's operator tools have their own context and permissions.Standard
Commission calculations
Yes — workflow contextFirm and preparer context can include names and related records. Do not assume all financial context is anonymous.Standard
Analytics & usage patterns
Yes — workflow-dependentSome requests use firm-wide totals; some client, preparer and case features can include details about individuals.Low

AI Security Controls

Updated September 2026

Every AI interaction on the GoRefer platform is governed by the following technical and policy controls. The status column shows whether each one is a working control, a policy commitment or still open; open items are listed rather than left off the page.

ControlDescriptionStatus
Firm isolation
Firm AI features only query that firm's data and check the user's authorization. Public features and GoRefer's operator tools have separate context and permissions.Enforced
No model training on customer data
GoRefer policy prohibits using customer inputs to train or fine-tune models. How the provider handles data is governed by the applicable Microsoft service terms and our configuration.Policy
Identifier filtering in case context
When Gio assembles a case for the AI, it leaves out supported identifier fields and redacts identifier patterns from free text. This does not cover every input to every AI feature, or the original files sent for document recognition. Client names may remain.Enforced
AI response audit log
Gio stores conversation content and workflow records, as well as audit metadata. Case-linked records are currently removed by an automatic cleanup 90 days after the case is created.Enforced
AI disclosure on preparer-facing outputs
Every Gio surface a preparer reads — chat, case chat, tax research, 1040 return review, IRS notice analysis and drafted responses, memos, review queues, due-diligence output and content drafts — carries a standing, non-dismissible notice that the output is AI-assisted and must be reviewed and verified before it is relied on.Enforced
AI disclosure on client-facing AI
The AI surfaces a taxpayer or website visitor interacts with directly — the embeddable Gio chat widget and the conversational client intake among them — do not yet carry a taxpayer-worded version of that notice. We have not yet decided whether one is required or how it should be worded, so this control is still open.Open
Professional review before reliance
AI outputs are presented as drafts. Conversation messages and generated work can be saved as part of the workflow. Preparers remain responsible for reviewing AI output before using it in client work.User responsibility
Fallback infrastructure
Gio uses Microsoft Foundry, with Azure OpenAI as a fallback; both run on Microsoft infrastructure. How long Microsoft keeps data depends on the applicable service terms and our configuration.Enforced
Prompt-injection risk controls
Input handling, structured context and prompt instructions reduce prompt-injection risk. These measures do not guarantee that every malicious instruction is detected or blocked.Enforced

AI Credit System as a Governance Mechanism

Updated September 2026

GoRefer's AI credit system is not just a billing mechanism — it serves as a natural rate-limiting and auditability layer. Metered Gio operations record credit usage. A billing record is not a complete audit of every data access or AI interaction.

Rate Limiting

  • Metered operations check available credits alongside their access controls

  • Administrators can review credit usage for unexpected activity

  • Admins can set per-user AI credit limits

Usage records

  • Metered operations record usage details for the applicable action

  • Credit history supports usage review; it is not a tamper-proof event archive

  • Credit history is recorded separately from case-content retention

Access Control

  • Credit allocations are scoped per user role

  • Authorized administrators can manage supported user access and limits

  • AI features follow the same RBAC as the rest of the platform

AI Infrastructure Isolation

Updated September 2026

How long providers keep data depends on the service

How Microsoft processes, stores and retains data depends on the service, our configuration and the applicable terms. GoRefer also stores conversation and case records. Not every request uses a zero-retention service; ask us for the current provider setup.

Request Lifecycle

  • Context is put together on GoRefer's own systems

    Supported identifiers are filtered out of case details. Other inputs, including original documents, are processed separately; names and narrative can remain.

  • Requests and conversations

    Gio can carry a conversation across requests, using conversations kept with the AI provider where set up and messages stored by GoRefer

  • Response handling

    Each feature handles structured answers and AI refusals in its own way; professional review is still required

  • No cross-firm context

    The context sent with each request comes only from the requesting firm

Failure & Fallback Handling

  • Primary and fallback providers

    Supported features can fall back from Microsoft Foundry to Azure OpenAI; terms and retention for each service are available on request

  • When a provider fails

    Gio shows an unavailable or error message. Conversation and case records already stored follow their own retention schedule

  • Incident logging

    Failure logging varies by feature; details of logging and data filtering are available on request

Prompt Injection Protection

Updated September 2026

Prompt injection is a class of attack where malicious input attempts to override AI instructions, extract data from the AI context, or cause unintended behavior. GoRefer applies multiple layers of defense against these attacks.

Input Defense

  • User inputs are sanitized before inclusion in AI prompts

  • Input structure and prompt instructions reduce risk; they do not guarantee injection detection

  • Text from clients is kept separate from Gio's own instructions

  • Request-size and field-length limits depend on the feature

Output Defense

  • Features that need structured answers validate them

  • There is no universal filter that blocks personal data in AI responses

  • Rendering and sanitization controls reduce risk on supported screens

  • Independent prompt-injection testing is a goal; ask us for the scope and results of any completed test