Tax documents contain Social Security numbers, account information, income data, and other sensitive information. The method used to exchange them matters.
Prefer a secure portal
A professionally managed client portal is generally preferable to sending unencrypted tax documents as ordinary email attachments. Ask whether multifactor authentication and controlled access are supported.
Be cautious with links and requests
Phishing attacks often imitate legitimate tax or financial communications. Verify unexpected portal invitations or document requests through a known contact method before entering credentials.
Ask how the firm handles data
Technology is only part of security. Ask how access is limited, how paper records are handled, and how long records are retained.
Do not put sensitive tax documents into a basic website contact form
A public intake form should be used to describe your needs—not to send Social Security numbers, account numbers, complete tax returns, or other highly sensitive documents. Those belong in the firm’s secure document system after an engagement process begins.