IRC §7216 compliancefor tax software on client files

IRC §7216 is a federal criminal statute. It bars tax return preparers from disclosing taxpayer return information to unauthorized third parties, including most consumer AI tools. Feather is AI tax software for CPAs, EAs, and tax attorneys. This page is the 7216 compliance controls we run so a firm can put client files in the product. Encryption, isolation, and SOC 2 live on the Security page.

Controls and sources

What 7216 compliance looks like in the product

  • Gemini Enterprise models only. The main product runs on Gemini Enterprise. Taxpayer return information is not sent to consumer Gemini, ChatGPT, or other consumer AI products.

  • Language models stay in a US Google Cloud region. The product will not run if they point at a global or offshore region. Document AI and observability that touch taxpayer return information are pinned the same way.

  • No training on taxpayer return information. Queries, uploaded files, and client information are not used to train, fine-tune, or improve any AI model. Google's Gemini Enterprise training restriction says the same thing: Google will not use your data to train or fine-tune models without prior permission.

  • Client files sit in us-central1. Uploads go to Google Cloud Storage in that region.

  • Data minimization, then TriRedactor. Fillable returns are read in-process. Taxpayer values never enter a model request; only a blank IRS template is sent to label field names. Form mapping uses the return's own text layer when it is present, so a filled PDF is not sent to Vision unless it is a scan. When tax-review text or a web-search query does leave the process, TriRedactor replaces SSNs, EINs, and TINs with irreversible tokens first. The same redaction runs on observability traces before export.

  • Gemini Enterprise platform terms. The main product sits on the Gemini Enterprise Agent Platform. Isolation, SLAs, governance, and zero data retention come with that platform. Consumer AI products do not offer those terms.

  • A complete audit trail. Every query and response is logged, timestamped, and retained until the firm deletes it. Cloud-drive reads, and exports back to Drive or OneDrive, emit a structured audit entry. Nothing auto-deletes.

  • Clerk holds authentication and OAuth credentials. User accounts, sessions, and MFA are handled by Clerk, a US-hosted identity provider with a SOC 2 Type II attestation. Cloud-drive OAuth credentials (Google Drive, OneDrive, Dropbox, Box) stay on Clerk's infrastructure. Feather does not store those refresh tokens. File bytes move between Feather and the drive provider; they do not pass through Clerk.

  • Confidentiality and written consent. The Terms of Service include a confidentiality clause. Firms warrant they hold the consents required to upload client files, including Rev. Proc. 2013-14-aligned written consent where §7216 requires it.

  • SOC 2 Type I attested. Feather has completed a SOC 2 Type I audit. The full security program is on the Security page.

  • SOC 2 Type II pending. A SOC 2 Type II examination is in progress.

  • Encryption at rest and in transit. Data at rest is encrypted with AES-256. Connections use TLS 1.2+. Full detail is on the Security page.

  • Customer isolation. Architecture keeps customer data strictly separated. There is no cross-talk between accounts. Full detail is on the Security page.

  • Google's zero data retention docs. The Gemini Enterprise Agent Platform zero data retention page covers the training restriction and the configuration required so prompts and responses are not retained by Google.

  • Google's Gemini Enterprise Agent Platform intro. The introduction to Gemini Enterprise Agent Platform describes the enterprise platform we run on, including model serving, isolation, and governance.

  • Clerk's security page. Clerk's security and compliance summary covers its SOC 2 Type II report, US-hosted infrastructure, and identity controls. Cloud-drive OAuth credentials live there, not in Feather.

  • Feather's Security page. Encryption, tenant isolation, and the rest of the infrastructure picture live on the Security page. This list is the §7216-specific set.

For your firm's WISP: this page is the 7216 compliance list. Pair it with the Security page for encryption, isolation, and the FTC Safeguards / IRS Publication 4557 controls.

The AI a CPA can put a client file in.

Try 3 questions instantly. Sign up for your full 7-day free trial - no credit card required.

Explore the AI tax assistant or compare against other AI tax research tools