Pumpkin
    Data Encryption

    Client Data Encryption for the Day a Laptop Goes Missing

    AES-256 on what's stored, TLS 1.3 on what's moving, and key management that doesn't depend on anyone remembering. Encryption your firm can actually document.

    Every Place a Return Sits

    Files at rest, files in flight, files in backup, and the keys that open all three. A gap in any one of those makes the other two decorative.

    AES-256 on What's Stored

    Everything sitting on your machines, servers, and backups is encrypted. If a laptop gets left in an airport, the returns on it stay unreadable.

    TLS 1.3 on What's Moving

    Portal sessions, file transfers, and mail in flight are encrypted with current TLS. The part of the trip you can't see is the part that gets intercepted.

    Keys Somebody Manages

    Rotation, access logging, and escrow, handled. Encryption fails in practice because of key management, not because the math broke.

    Encryption Status at a Glance

    One screen showing which machines, drives, and shares are encrypted and which aren't. The interesting row is always the one nobody expected: the old laptop a seasonal preparer still has at home, or the share somebody set up in 2021 for a single engagement.

    • Encrypted Backups

      Backups are encrypted before they leave your network and stay encrypted off-site. We test restores too, because an untested backup is a rumor.

    • File-Level Encryption

      Individual returns, workpapers, and statements stay encrypted on shared drives, which is where documents quietly pile up.

    • Automatic Key Rotation

      Keys rotate on a schedule, with no downtime and no ticket for you to open.

    • Zero-Knowledge Storage

      Only your authorized people can decrypt what's stored. We can't read your client files, which is the correct arrangement.

    app.pumpkin.cloud/encryption/status

    Encryption Status Panel

    All Secure
    Workstations (12/12)
    Encrypted
    File Server (Tax Returns)
    AES-256
    Cloud Backup Storage
    Encrypted
    Email Attachments (In Transit)
    TLS 1.3
    USB Drives Policy
    Blocked

    Who It's For

    Anyone holding financial or taxpayer data, which in this business is everyone

    Tax Preparers

    W-2s, 1099s, and finished returns encrypted wherever they sit, including that folder somebody made on the desktop.

    Audit Firms

    Workpapers and draft statements protected end to end, including the versions emailed at 11pm.

    Bookkeeping Services

    Bank statements, payroll files, and client records encrypted at rest and in transit across the practice.

    Wealth Managers

    Portfolio detail and estate documents, the kind of file that would be genuinely damaging in the wrong hands.

    app.pumpkin.cloud/encryption/key-management

    Key Management Console

    Primary AES-256 Key

    Rotated 3 days ago

    Active

    Backup Encryption Key

    Rotated 7 days ago

    Active

    TLS Certificate

    Renewed 14 days ago

    Active

    Legacy Key (v2)

    Expired

    Archived

    Automated Key Management

    Keys rotate, get logged, and stay stored somewhere sensible. An expired certificate is a boring way to take your client portal offline in March, so we watch the dates.

    The audit trail shows when each key was created, rotated, and used. That's the documentation an IRS review or a SOC 2 auditor asks for, and it's far easier to produce when the system has been keeping it all along.

    Frequently Asked Questions

    What encryption do you actually use?

    AES-256 for data at rest, TLS 1.3 for data in transit. Neither is an exotic choice. They're the current defaults for anyone serious about protecting financial records, and they're what IRS Publication 4557 points at when it talks about encryption.

    Will encryption slow the office down?

    You won't notice it. Encryption and decryption happen at the filesystem and transport level, and any processor made in the last decade handles it without effort. What slows a firm down in March is the practice software, not the crypto.

    How do encrypted backups work?

    Data is encrypted before it leaves your systems, travels over an encrypted channel, and sits encrypted off-site. If a backup drive were stolen, it would be an expensive paperweight. We also run test restores, because a backup nobody has ever restored from is a guess.

    What happens if a key is lost?

    Keys are escrowed in more than one secure location and recoverable through a verified authorization process. Losing access to your own data is a genuine risk with encryption done badly, which is exactly why key management is part of the service rather than a box you tick alone.

    Does encryption satisfy IRS requirements?

    It covers a specific piece of them. Publication 4557 calls for encrypting taxpayer data at rest and in transit, and we document the controls so you can show your work. Encryption on its own isn't compliance, and anyone telling you otherwise is selling something.

    Find the Files That Aren't Encrypted Yet

    We'll inventory where client data actually lives, encrypt what isn't, and hand you documentation you can show an auditor. There's usually one surprise in the inventory.