Skip to main content
Hearth Agency
Security & Data Use

Know what data moves, what stays separate, and what each system is allowed to see

Hearth separates workflow information from tax documents, ties protected-data movement to the applicable consent, limits access by role, and makes those boundaries visible so a firm's security review does not have to infer them.

The security model

Five control planes. One purpose: keep the wrong data out of the wrong system

The security model defines separate control responsibilities for client workflow, tax documents, identity/access, AI-tool use, and audit/log records rather than treating every kind of information as one undifferentiated data environment.

01

Workflow plane

Client-relationship metadata, scheduling, campaign state, consent status, and secure handoff links.

02

Tax-document plane

Returns, source documents, working papers, and protected professional work stay in the controlled tax/accounting environment.

03

Identity & access plane

Role-based provisioning, MFA, service-provider oversight, incident-response controls, and attributable access.

Review access controls ↓
04

AI-tool plane

AI-assisted workflows are subject to defined data-access boundaries. Tool visibility and human-review points are disclosed separately.

Review AI Disclosure →
05

Audit & log plane

Relevant authorization, access, tool, and handoff events are recorded to the extent implemented so the engagement path can be reconstructed.

Review audit controls ↓
The workflow layer — currently GHL

What is permitted in the workflow layer—and what belongs elsewhere

The workflow layer supports communication, scheduling, routing, and authorization state. Whether a particular field may be used or disclosed there depends on how the information was obtained, the purpose of the use or disclosure, and the applicable legal, professional, contractual, and security requirements. Tax returns, source documents, working papers, and sensitive strategy economics belong in the applicable controlled professional environment instead.

Permitted in the workflow layer when applicable requirements are satisfied

Relationship and routing information

  • Client name, firm name, and role, when permitted for that workflow and data source.
  • Contact fields the firm is permitted to use in that workflow.
  • Campaign or sequence state.
  • Scheduling events and appointment metadata.
  • Secure handoff links into the controlled document environment.
  • Authorization or consent status, where applicable to the relevant data flow.
Not permitted in the workflow layer

Tax documents and sensitive professional material

  • Federal or state tax returns, draft or final.
  • W-2s, 1099s, K-1s, bank statements, and brokerage statements.
  • Working papers, reconciliations, and methodology notes.
  • Journal entries or general-ledger detail.
  • Reasonable-compensation figures.
  • Legacy economics or other protected material that is not authorized for that environment under the applicable legal, professional, contractual, and security requirements.
Access, security program & audit trail

Control who gets access—and preserve the events needed to reconstruct what happened

The access-control standard is built around identifiable users, function-based access, appropriate authentication controls, and the written information security program that applies to the environment holding the data.

Role-based access

Give the role only what it needs.

The provisioning standard limits visibility by function rather than treating broad access as the default.

Identity & authentication

Use identifiable accounts and MFA.

The control standard calls for identifiable user access and multi-factor authentication, or another permitted equivalent control, where applicable.

Written security program

Access belongs to a governed process.

Provisioning, service-provider oversight, incident response, and other safeguards are governed by the written information security program applicable to that entity and environment.

Audit trail

Log the control events that matter.

The logging standard covers relevant consent, access changes, system handoffs, and applicable tool activity to the extent implemented so the engagement path can be reconstructed.

Authoritative security guidanceTax-preparation firms are among the entities the FTC identifies as financial institutions under the Safeguards Rule, subject to the Rule's coverage and jurisdiction. Covered financial institutions must maintain a written information security program. IRS Publication 4557 provides tax-professional data-security guidance.
Continue with the diligence question you still have.Responsibility and professional accountability → Governance. AI tools, data visibility, and human review → AI Disclosure. Shorter consolidated review → Trust.
Ready to evaluate the capability itself?

Evaluate the capability your firm is considering

Each capability keeps these control boundaries, then adds the workflow and diligence specific to the work itself.