Skip to content

GoRefer Trust Center

Compliance

Updated September 2026

About this page. The procedures and recovery times described here are our policies and targets. They are not an independent audit, a contractual SLA or proof that a scheduled review has taken place. For current details, assessment reports and records, make a request through the Trust Portal.

GoRefer publishes documentation of its application controls and the policies relevant to tax firms. The summaries below separate what is built into the product, what is policy and what our operational records can show; they are not an independent audit opinion or a finding that any firm is compliant.

SOC 2 · Status in progress
GDPR rights & policies
Privacy rights policy
HIPAA: no attestation
IRS 4557 control support

Compliance Roadmap

GDPR

Ongoing

Privacy rights policy

IRS 4557

Ongoing

Technical control support

CCPA

Ongoing

Rights request process

SOC 2 Type II

Status on request

Not yet attested

ISO 27001

No confirmed date

Roadmap target

SOC 2 Type II

Roadmap 2026

Updated September 2026

SOC 2 Type II — audit in progress

GoRefer's SOC 2 Type II audit is in progress and we are not yet attested. The table below summarizes our product and policies; it is not an auditor's conclusion. You can request current audit details and control documentation through the Trust Portal.

The table organizes product and policy information by the AICPA Common Criteria. It does not establish complete coverage or auditor acceptance of any criterion.

Trust Service CriteriaStatusProduct and policy summary
CC1 – Control Environment
Code + policyFirm and platform role controls; staff training, responsibility and access-review policies (records on request)
CC2 – Communication
Published policyTrust Center, privacy notices, subprocessor register, notification policy and public documentation changelog
CC3 – Risk Assessment
Code + policyPlatform security signals and vulnerability reporting; current risk assessment and follow-up records on request
CC4 – Monitoring Activities
Code + policyAudit records for supported features, integrity checks on chained records, and error reporting; coverage details on request
CC5 – Control Activities
Code + policyRole checks, two-factor authentication, sign-in session rotation and restricted intake access; not yet independently verified
CC6 – Logical & Physical Access
Code + policyFirm-scoped data access and privileged platform access; physical security and hosting-provider settings are covered separately, with details on request
CC7 – System Operations
Published policyIncident severity and response targets, backup review and recovery planning; completed incident and restore records on request
CC8 – Change Management
Code + policyVersion-controlled code and automated build checks; release approvals, test results and change records on request
CC9 – Risk Mitigation
Published policyRecovery targets, vendor-term review and account-retention procedures; current agreements and test records on request

Request SOC 2 Roadmap

Enterprise customers and prospects can request our detailed SOC 2 readiness roadmap, including gap analysis and remediation timeline, via the Trust Portal.

IRS Publication 4557 — Safeguarding Taxpayer Data

IRS 4557

Updated September 2026

IRS Publication 4557 defines security requirements for all tax professionals who handle taxpayer data. GoRefer is designed specifically for tax firms and provides technical controls that can support parts of a firm’s security program. The firm remains responsible for its legal obligations and operational practices.

IRS RequirementHow GoRefer Addresses ItStatus
IRS Rev. Proc. 2007-40 / Pub. 4557Data Security PlanDocumented
Written Information Security Plan (WISP)Internal security policy document, updated annuallyDocumented
Taxpayer data encryptionAES-256-GCM on supported sensitive fields; HTTPS; storage encryption details on requestDocumented
Access controlsRBAC with least-privilege, MFA and role-based access controlsDocumented
Incident responseDocumented IR plan with IRS notification requirementsDocumented
Employee trainingAnnual security awareness training programDocumented
Vendor due diligenceProvider-term and annual-review policy; current agreements and review records on requestDocumented

GDPR Compliance

GDPR

Updated September 2026

Data Controller Responsibilities

  • Lawful basis documented for every data processing activity

  • Privacy notices served at collection points

  • Data minimization — only collect what is needed

  • Purpose limitation — no secondary uses without re-consent

  • Privacy-request policy targets and applicable legal timelines

Subprocessor Management

  • Provider terms, DPAs and transfer provisions: available on request

  • Subprocessor register maintained and published (see Subprocessors page)

  • Customer notification of new subprocessors with 30-day opt-out window

  • Annual provider-review policy; completed reviews on request

HIPAA Readiness

Scope Review Required

Updated September 2026

HIPAA scope and agreements

GoRefer’s tax-workflow controls do not establish HIPAA compliance. A tax return involving health-related information does not by itself determine HIPAA status. Contact privacy@gorefer.io to discuss your use case and available agreements before treating the service as suitable for protected health information.

Technical Safeguards

  • Encryption for supported sensitive fields

  • TLS-protected connections

  • MFA and access controls

  • Workflow-specific audit events

Administrative Safeguards

  • Ask us who our responsible security officer is

  • Annual training policy; completion records on request

  • Access authorization procedures

  • Sanction policy for violations

Agreement Review

  • Talk to us about whether it suits your use case

  • Request via security@gorefer.io or Trust Portal

  • A DPA is not a BAA or independent assurance

CCPA / CPRA

CCPA

Updated September 2026

Consumer Rights (California)

  • Right to know what personal information is collected

  • Right to delete personal information

  • Right to opt-out of sale (GoRefer does not sell data)

  • Right to non-discrimination for exercising rights

  • Right to correct inaccurate personal information

How to Exercise Rights

  • Email privacy@gorefer.io with subject 'CCPA Request'

  • Include your name, email address, and the right you wish to exercise

  • Verified identity required before processing sensitive requests

  • Response within 45 days (extendable to 90 days with notice)