GoRefer Trust Center
Compliance
Updated September 2026
About this page. The procedures and recovery times described here are our policies and targets. They are not an independent audit, a contractual SLA or proof that a scheduled review has taken place. For current details, assessment reports and records, make a request through the Trust Portal.
GoRefer publishes documentation of its application controls and the policies relevant to tax firms. The summaries below separate what is built into the product, what is policy and what our operational records can show; they are not an independent audit opinion or a finding that any firm is compliant.
Compliance Roadmap
GDPR
Ongoing
Privacy rights policy
IRS 4557
Ongoing
Technical control support
CCPA
Ongoing
Rights request process
SOC 2 Type II
Status on request
Not yet attested
ISO 27001
No confirmed date
Roadmap target
SOC 2 Type II
Updated September 2026
SOC 2 Type II — audit in progress
GoRefer's SOC 2 Type II audit is in progress and we are not yet attested. The table below summarizes our product and policies; it is not an auditor's conclusion. You can request current audit details and control documentation through the Trust Portal.
The table organizes product and policy information by the AICPA Common Criteria. It does not establish complete coverage or auditor acceptance of any criterion.
| Trust Service Criteria | Status | Product and policy summary |
|---|---|---|
CC1 – Control Environment | Code + policy | Firm and platform role controls; staff training, responsibility and access-review policies (records on request) |
CC2 – Communication | Published policy | Trust Center, privacy notices, subprocessor register, notification policy and public documentation changelog |
CC3 – Risk Assessment | Code + policy | Platform security signals and vulnerability reporting; current risk assessment and follow-up records on request |
CC4 – Monitoring Activities | Code + policy | Audit records for supported features, integrity checks on chained records, and error reporting; coverage details on request |
CC5 – Control Activities | Code + policy | Role checks, two-factor authentication, sign-in session rotation and restricted intake access; not yet independently verified |
CC6 – Logical & Physical Access | Code + policy | Firm-scoped data access and privileged platform access; physical security and hosting-provider settings are covered separately, with details on request |
CC7 – System Operations | Published policy | Incident severity and response targets, backup review and recovery planning; completed incident and restore records on request |
CC8 – Change Management | Code + policy | Version-controlled code and automated build checks; release approvals, test results and change records on request |
CC9 – Risk Mitigation | Published policy | Recovery targets, vendor-term review and account-retention procedures; current agreements and test records on request |
Request SOC 2 Roadmap
Enterprise customers and prospects can request our detailed SOC 2 readiness roadmap, including gap analysis and remediation timeline, via the Trust Portal.
IRS Publication 4557 — Safeguarding Taxpayer Data
Updated September 2026
IRS Publication 4557 defines security requirements for all tax professionals who handle taxpayer data. GoRefer is designed specifically for tax firms and provides technical controls that can support parts of a firm’s security program. The firm remains responsible for its legal obligations and operational practices.
| IRS Requirement | How GoRefer Addresses It | Status |
|---|---|---|
| IRS Rev. Proc. 2007-40 / Pub. 4557 | Data Security Plan | Documented |
| Written Information Security Plan (WISP) | Internal security policy document, updated annually | Documented |
| Taxpayer data encryption | AES-256-GCM on supported sensitive fields; HTTPS; storage encryption details on request | Documented |
| Access controls | RBAC with least-privilege, MFA and role-based access controls | Documented |
| Incident response | Documented IR plan with IRS notification requirements | Documented |
| Employee training | Annual security awareness training program | Documented |
| Vendor due diligence | Provider-term and annual-review policy; current agreements and review records on request | Documented |
GDPR Compliance
Updated September 2026
Data Controller Responsibilities
Lawful basis documented for every data processing activity
Privacy notices served at collection points
Data minimization — only collect what is needed
Purpose limitation — no secondary uses without re-consent
Privacy-request policy targets and applicable legal timelines
Subprocessor Management
Provider terms, DPAs and transfer provisions: available on request
Subprocessor register maintained and published (see Subprocessors page)
Customer notification of new subprocessors with 30-day opt-out window
Annual provider-review policy; completed reviews on request
HIPAA Readiness
Updated September 2026
HIPAA scope and agreements
GoRefer’s tax-workflow controls do not establish HIPAA compliance. A tax return involving health-related information does not by itself determine HIPAA status. Contact privacy@gorefer.io to discuss your use case and available agreements before treating the service as suitable for protected health information.
Technical Safeguards
Encryption for supported sensitive fields
TLS-protected connections
MFA and access controls
Workflow-specific audit events
Administrative Safeguards
Ask us who our responsible security officer is
Annual training policy; completion records on request
Access authorization procedures
Sanction policy for violations
Agreement Review
Talk to us about whether it suits your use case
Request via security@gorefer.io or Trust Portal
A DPA is not a BAA or independent assurance
CCPA / CPRA
Updated September 2026
Consumer Rights (California)
Right to know what personal information is collected
Right to delete personal information
Right to opt-out of sale (GoRefer does not sell data)
Right to non-discrimination for exercising rights
Right to correct inaccurate personal information
How to Exercise Rights
Email privacy@gorefer.io with subject 'CCPA Request'
Include your name, email address, and the right you wish to exercise
Verified identity required before processing sensitive requests
Response within 45 days (extendable to 90 days with notice)