Always on.
Always Secure.
From encryption to access control, Pernee holds returns, workpapers and review history to the standard your firm is held to. It never trains on your data and never writes back into your tax software.

Pernee is committed to maintaining compliance with
the most rigorous international safety and security standards.
SOC 2 Type II
The independent audit of how Pernee secures, processes and monitors client data across every system is underway.
ISO 27001
Pernee’s information security management system is being built and audited against the international standard.
IRC Section 7216
Tax return information is used only to prepare and review the return it belongs to. It is never disclosed or used for anything else.
CCPA / CPRA
Personal information is collected, stored and deleted to California’s privacy requirements, for every client in every state.
Trusted data storage
Hosted in the United States
Client data is stored and processed in the US. Office files are converted to text inside Pernee’s own infrastructure, never by a third-party extraction service.
Isolated by firm and by client
Every row is scoped to your organization and enforced by row-level security at the database. No other customer can reach it.
No model training
Neither Pernee nor its model providers train, fine-tune or improve any model on your returns, workpapers or review comments. Zero data retention is mandatory on every request.
Firm-grade security
Permissions mirror your firm
A person sees in Pernee exactly what they can already open in SharePoint, OneDrive, Outlook and Teams. Access is checked on every request and never widened.
Your approval required
Pernee staff can reach customer data only for a support issue, and only with written approval from your firm. Every access is logged.
Regular security testing
The full platform is penetration-tested by an outside firm, and findings are fixed and retested before they are closed.
Drafts only
Pernee never files anything and never writes back into your tax software. Every agent output is a draft for a person to approve.
Your firm controls its data
at all times.
Pernee follows the access rules your firm already has. You decide which sources are connected, how long data is kept, who can sign in and what each person can see, and you can review every read and export in the audit log.
Data retention
Set retention periods that match your firm’s record-keeping policy and the client engagement letter.
Audit log
Sign-ins, role changes, reads, questions and exports are logged with the person and the time.
Encryption
TLS 1.2+ in transit and AES-256 at rest. Integration credentials are never stored in plaintext.
Single sign-on
Sign in with your firm’s Microsoft or Google identity, so access ends the day someone leaves.
FAQs
All data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Credentials for connected systems are encrypted and never stored in plaintext.
Return data is used only to prepare and review that client’s return, in line with IRC Section 7216. It is visible only to the people at your firm who could already open it, and Pernee staff never access it without your written approval.
Yes. Every answer and every agent draft cites the documents, prior-year returns and review comments it relied on, so a reviewer can open the source and verify it before anything is approved.
You can export everything at any time. When the contract ends, all files, indexes and memory for your firm are permanently deleted, and we confirm the deletion in writing.
