Know what data moves, what stays separate, and what each system is allowed to see
Hearth separates workflow information from tax documents, ties protected-data movement to the applicable consent, limits access by role, and makes those boundaries visible so a firm's security review does not have to infer them.
Five control planes. One purpose: keep the wrong data out of the wrong system
The security model defines separate control responsibilities for client workflow, tax documents, identity/access, AI-tool use, and audit/log records rather than treating every kind of information as one undifferentiated data environment.
Workflow plane
Client-relationship metadata, scheduling, campaign state, consent status, and secure handoff links.
Tax-document plane
Returns, source documents, working papers, and protected professional work stay in the controlled tax/accounting environment.
Identity & access plane
Role-based provisioning, MFA, service-provider oversight, incident-response controls, and attributable access.
Review access controls ↓AI-tool plane
AI-assisted workflows are subject to defined data-access boundaries. Tool visibility and human-review points are disclosed separately.
Review AI Disclosure →Audit & log plane
Relevant authorization, access, tool, and handoff events are recorded to the extent implemented so the engagement path can be reconstructed.
Review audit controls ↓What is permitted in the workflow layer—and what belongs elsewhere
The workflow layer supports communication, scheduling, routing, and authorization state. Whether a particular field may be used or disclosed there depends on how the information was obtained, the purpose of the use or disclosure, and the applicable legal, professional, contractual, and security requirements. Tax returns, source documents, working papers, and sensitive strategy economics belong in the applicable controlled professional environment instead.
Relationship and routing information
- Client name, firm name, and role, when permitted for that workflow and data source.
- Contact fields the firm is permitted to use in that workflow.
- Campaign or sequence state.
- Scheduling events and appointment metadata.
- Secure handoff links into the controlled document environment.
- Authorization or consent status, where applicable to the relevant data flow.
Tax documents and sensitive professional material
- Federal or state tax returns, draft or final.
- W-2s, 1099s, K-1s, bank statements, and brokerage statements.
- Working papers, reconciliations, and methodology notes.
- Journal entries or general-ledger detail.
- Reasonable-compensation figures.
- Legacy economics or other protected material that is not authorized for that environment under the applicable legal, professional, contractual, and security requirements.
Start with the rule that applies to the use or disclosure
Section 7216 generally restricts a tax return preparer's use or disclosure of tax return information. Some uses and disclosures are permitted by regulation without separate taxpayer consent; others require consent before the information is used or disclosed.
Control who gets access—and preserve the events needed to reconstruct what happened
The access-control standard is built around identifiable users, function-based access, appropriate authentication controls, and the written information security program that applies to the environment holding the data.
Give the role only what it needs.
The provisioning standard limits visibility by function rather than treating broad access as the default.
Use identifiable accounts and MFA.
The control standard calls for identifiable user access and multi-factor authentication, or another permitted equivalent control, where applicable.
Access belongs to a governed process.
Provisioning, service-provider oversight, incident response, and other safeguards are governed by the written information security program applicable to that entity and environment.
Log the control events that matter.
The logging standard covers relevant consent, access changes, system handoffs, and applicable tool activity to the extent implemented so the engagement path can be reconstructed.
Evaluate the capability your firm is considering
Each capability keeps these control boundaries, then adds the workflow and diligence specific to the work itself.
