Every document on your desk in March is a Social Security number.
Extraction, substantiation and review — the three places busy season actually goes — run on the highest concentration of personally identifiable information your firm will ever hold.
Where the hours go
Volume, compressed into ten weeks. Thousands of client documents arrive as photographs, scans and PDFs and someone types the values into the tax software. Credits need substantiating across ledgers and project notes. Ledgers need reviewing for the thing that looks wrong. IRS Publication 4557 and the GLBA Safeguards Rule both make where that data goes the firm’s responsibility — including where a staff member sent it at 11pm in March.
Document extraction at intake
W-2s, 1099s, K-1s and loose receipts read and turned into structured values ready for the tax software, with the source document referenced for every figure so a reviewer can check it.
Tax documents are the densest PII a firm handles — names, addresses, SSNs, income, dependants, all on one page. Uploading them to a cloud LLM is the exact thing a written information security program exists to prevent.
R&D credit substantiation
General ledgers, project notes and internal correspondence scanned for qualifying activity, drafted into a citable justification memo an examiner can follow back to source.
This is proprietary corporate financial detail belonging to clients who did not agree to have it processed by a vendor. Keeping it inside the firm keeps the firm out of the blast radius when a cloud provider is breached.
Anomaly and duplicate detection
Deep analytical sweeps across millions of ledger rows, surfacing unusual patterns, duplicate invoices and the transactions worth a second look before an audit finds them.
Sweeping an entire general ledger through a metered API is priced per token and gets rationed until it stops happening. A system you own has a fixed cost, so the sweep runs on every engagement instead of the ones that seemed worth it.