Tax document security guide
How a solo tax preparer can collect documents without email attachments
Replace reply attachments with a defined upload workflow, then make that workflow one control inside your practice's broader written security program.
Updated August 28, 2026 · Workflow reviewed against current IRS and FTC guidance
Sensitive tax files need more than a convenient upload button.
A useful process controls who receives the request, how clients upload, what staff can access, and when files move into the practice's records system.
-
Email replies can scatter attachments across inboxes, forwards, and devices.
-
A loose folder does not explain which requested tax items remain incomplete.
-
No software product by itself creates a complete written information security program.
Does a secure upload link make a tax practice compliant?
No. FTC guidance describes a written information security program appropriate to the business, and IRS Publication 4557 discusses a broader set of safeguards. A document collection tool is one part of that work.
Why move tax attachments out of email?
A controlled upload path keeps the requested item, file, receipt, review state, and access controls together instead of scattering documents across reply threads.
What should a tax-document email contain instead of attachments?
Use the email as a notice: identify the tax year, state a truthful requested-by date, provide one current private upload link, and explain how to ask a question. Keep the tax files in the upload workflow and send any optional PIN separately from the link.
Can a solo tax preparer collect documents without client accounts?
Yes. A private request link can take the client directly to an itemized checklist. RequestFlow lets the client upload without an account and lets the one-person practice track each item as missing, received, accepted, or needing replacement.
Use a layered collection workflow.
Match controls to your practice, document the process, and periodically review whether the workflow still fits.
-
1
Send each client a private, revocable request link and verify the intended recipient.
-
2
Use a separate channel for a PIN when the request needs additional protection.
-
3
Collect files against named checklist items and confirm receipt without exposing document details in email.
-
4
Review, reject, or request replacements before exporting approved files.
-
5
Move finished records into the system governed by your retention policy and remove access when no longer needed.
Put each part of the tax-document handoff in the right channel
Email can notify the client, but it does not need to carry the tax file, the PIN, and the full document history. Adapt this four-channel matrix to your written security program and client-verification process.
- Email notice
- Send the action, not the attachmentName the tax year, give the truthful requested-by date, include one current private upload link, and explain where the client can ask a question without attaching documents.
- Private checklist link
- Collect and track the filesList only the client-specific tax items, receive each file against its item, issue a receipt, and show whether the item is missing, received, accepted, or needs replacement.
- Separate channel
- Deliver an optional PINWhen a request uses a PIN, send it through a channel separate from the link and follow the recipient-verification steps in your practice's own process.
- Practice records system
- Keep the approved recordAfter review, export accepted files to the system governed by the engagement and retention policy; RequestFlow is not intended to be the permanent archive.
Controls to evaluate for a solo practice
- Professional email and multi-factor authentication
- Private links with expiration, revocation, and optional PINs
- Private file storage and server-side authorization
- Malware scanning before staff download
- Audit events, access review, backups, and a deletion routine
- A written information security plan appropriate to the practice
What RequestFlow does—and does not do
- RequestFlow supports private checklist links, no-account uploads, PIN and expiry controls, malware scanning, audit logs, and export controls.
- RequestFlow does not prepare returns, replace professional review, or manage every safeguard required by your practice.
- Using RequestFlow is not a guarantee of IRS, FTC, GLBA, or other legal compliance.
Common questions
Why cite IRS and FTC sources?
Primary sources make the guidance easier to verify and reduce the risk of overstating what a software product can guarantee.
Can clients upload without an account?
Yes. RequestFlow clients use a private checklist link; practices can also use PIN and expiry controls.
Where should completed files live?
Export approved files to the records system governed by your engagement, professional duties, and documented retention policy.
Try RequestFlow with one real client request.
Start with a client request you already send. Preview the client upload flow before inviting clients.