DepreciationConverter

Security & regulatory position

You're required to vet us.
So here is everything, in order.

As a tax preparer you are a financial institution under GLBA, your firm needs a written information security plan, and you are obliged to hold your vendors to safeguards by contract. On top of that, the IRS Office of Professional Responsibility now expects documented vetting of third-party AI tools under Circular 230 §10.36. None of that should require an email to sales, so it's on this page.

Why you don't need your client's consent

Treas. Reg. §301.7216-2(d)(1) permits a preparer to disclose tax return information to another preparer located within the United States for auxiliary services in connection with preparing the return, without the taxpayer's written consent — provided the service does not make substantive determinations or give advice affecting tax liability.

Transcribing a depreciation schedule into an import file is data entry: the classic auxiliary service named in the regulation. It is the same basis the established scan-and-populate vendors rely on, and it holds only while two things stay true.

Condition 1

Everything stays in the United States

Our servers and the AI endpoint that reads the schedule are both US-based. There is no offshore keying step and no offshore subprocessor. If any part of the pipeline moved abroad, you would need signed consent from every client — so it doesn't.

Condition 2

We never make a determination

The tool copies what the schedule states. It will not choose a depreciation method, a recovery period, a convention or a basis — even when it could guess correctly. A missing value comes back empty and flagged for you, never filled in.

The vetting checklist, answered

Mapped to what IRS OPR Alert 2026-19 and IRS Pub. 4557 ask you to establish about a tool before you use it on client data.

Where is the data processed?
Entirely within the United States, including the AI inference endpoint. No offshore processing, no offshore support access.
Is client data used to train AI models?
No. Not by us, and our AI subprocessor is contractually prohibited from training on API data. This is a compliance boundary, not a marketing line — training on return information would be a use outside the purpose you gave it to us for.
What data do you actually need?
Asset descriptions, dates, dollar amounts, methods and lives. We do not need SSNs or EINs, so they are detected and stripped from the text on upload and never written into an export file.
How long is it kept?
Uploads and extracted rows are deleted within 30 days automatically. A “delete now” button on every conversion removes them immediately.
How is it protected in transit and at rest?
TLS in transit; encrypted storage at rest; access to a conversion requires either your signed-in account or the unguessable link issued to the session that created it.
Who at your company can see it?
Access is limited to the engineers who operate the service, and only for a specific support request. There is no browsing of customer schedules.
Does the tool make professional judgments?
No. It transcribes and flags. Every ambiguity — an unresolvable method code, a category the source never stated, a column the schedule doesn't print — is surfaced for your decision and blocks the download until you resolve it.
What happens if it gets something wrong?
The tie-out is the control: a conversion cannot be downloaded unless the cost, prior depreciation and current depreciation you see on the PDF equal the sum of the extracted rows. If a file that ties still turns out wrong, we refund it.
What certifications do you hold?
SOC 2 Type I is in progress, Type II to follow. We would rather say that plainly than imply more. The US-only §7216 position and the retention limits are in force today.

Need this as an attachment for your WISP?

The vendor file has the security exhibit and a one-page summary you can drop straight into your written information security plan.

Open the vendor file →

References: Treas. Reg. §301.7216-2 · FTC Safeguards Rule, 16 CFR §314.4 · IRS Pub. 4557 · IRS Security Six. This page describes our practices; it is not legal advice about your firm's obligations.