How to send tax documents securely
A tax document is close to the worst thing you can lose control of: it carries a Social Security number, an address, income, employer, and bank details on one page. Here is what actually protects it in transit, and why the most common method, email, protects it least.
Why email is the weak option
Email feels safe because it's familiar, but it fails on four separate counts:
- Copies persist everywhere. An attachment lives in the sender's sent folder, the recipient's inbox, both providers' servers, and every device that syncs either mailbox. It stays there indefinitely, with no way to recall it.
- Forwarding is one click. Once sent, you have no control over where the document travels next, and no record of it.
- Mailboxes are the primary target. Most account compromises start with email. A breached inbox with years of tax attachments is an identity-theft kit.
- There is no receipt. You cannot prove what arrived, when it was opened, or by whom. That matters exactly when something goes wrong.
The IRS's own guidance for tax professionals points in the same direction: treat taxpayer data as sensitive at rest and in transit, and avoid sending it over channels you don't control.
The common alternatives, honestly rated
Password-protected PDFs
Better than a bare attachment, but the protection is thin: PDF passwords are commonly sent in the same email thread (defeating the point), the encryption on older PDF standards is weak, and the copies-everywhere problem is unchanged. Reasonable as a stopgap for a single document; unworkable as a system.
Encrypted email services
Services that encrypt the message body and attachments end to end solve the in-transit problem, if both sides use them correctly. For a firm's clients, that "if" is the catch: recipients face an unfamiliar inbox, extra passwords, and expiring links. The security is real; the completion rate suffers, and people fall back to regular email.
Consumer file-sharing links
A shared drive link beats an attachment: the file lives in one place and access can be revoked. But general-purpose sharing tools have no concept of a client, a tax year, or a request, so firms end up with a sprawl of links and folders, no record of who opened what, and documents landing wherever the client guessed they should go.
A client portal
A portal is the only option on this list designed for the whole job rather than a single send: documents travel encrypted, live in one access-controlled place instead of scattering as copies, and every exchange leaves a record. The failure mode is different: portals only work if clients actually use them. A portal that confuses clients sends them straight back to email attachments, which is how many firms end up paying for a portal and still working out of an inbox.
What to look for in a secure portal
Whichever product you evaluate, ours included, check for these:
- Two-factor authentication for clients, not just staff. The client's account is the one holding their documents.
- Sign-in that clients don't fumble. One-time links from the request email remove the forgotten-password wall that drives people back to attachments.
- Access control per folder, not per account. Staff-only areas, client-visible areas, and named access with expiry.
- Receipts. You should be able to prove a specific person received and opened a specific document at a specific time.
- Revocable, expiring shares. Any link that leaves the system should expire, be revocable, and stop working if forwarded.
- A way out. Your documents should export in bulk, in standard formats, without a support ticket.
For accounting firms: make the secure path the lazy path
Individual senders can pick a tool per document. A firm can't. During filing season the secure channel has to be the path of least resistance for hundreds of clients at once, or it silently loses to email. In practice that means: invitations branded as your firm (clients don't open links from vendors they've never heard of), an upload that never asks the client where to file, a way to photograph paper documents from a phone, and requests with reminders so the client always knows what's still needed.
That is the job BrightReturn is built for: a firm-branded portal with magic-link entry, scan-to-upload, and a named receipt for every document, at$25 per staff user per month. If you're evaluating options, thesecurity overview lists the specifics worth comparing.