SECURITY & ARCHITECTURE

There is no Sophicor server. There is no Sophicor cloud.

There's your Google Workspace, and software that runs inside it. This page explains exactly what that means, what leaves your environment, and — just as importantly — where our boundary ends.

Not connected to your Workspace. Inside it.

Most tax automation works the way you would expect software to work. Your documents are uploaded to a vendor's system, processed on the vendor's infrastructure, and the results are sent back to you. However careful that vendor is, your clients' most sensitive documents have spent time in a building you cannot point to, on hardware you cannot audit, alongside other firms' clients.

Sophicor Pro is not deployed that way. The application is built on Google Apps Script and is deployed into your firm's own Google Workspace. It executes under your account, in your tenancy, governed by the Google Workspace agreement your firm already signed. There is no Sophicor-controlled environment for it to run in, because we didn't build one.

This is the part that took the longest to build, and it is the part no screenshot can show you. It is also the reason the rest of this page can say what it says.

Google's own OCR. Under your account.

When a W-2 arrives, the text is extracted by Google's own optical character recognition, running inside your Workspace on your firm's credentials. The field values are then mapped and structured by the Sophicor application — which, as above, is also running inside your Workspace.

What this means in practice, stated plainly:

  • No third-party AI vendor. Your clients' documents are not sent to an outside model provider.
  • No new processor in the chain. The document is read by Google, under the agreement you already have with Google.
  • Nothing to add to your vendor list on account of the reading step.

Guided by Sophia AI, extraction produces a confidence score for every field. Nothing is trusted on that signal alone. A licensed professional reviews and verifies each value before it is used on a return. That review step is deliberate, and it is not optional.

Extraction quality is actively improving. Sophicor Pro is in beta and we refine it weekly, which is why you will not find an accuracy percentage anywhere on this site — we would rather show you the product than quote you a number we cannot yet stand behind.

One number. That's the whole list.

For billing, Sophicor needs to know how many clients your firm has. That count is read through your Workspace and your Stripe subscription, and the count is what reaches us.

Not the names. Not the documents. Not the returns. The number.

If you want a single sentence to give the partner who asks what this vendor can see, that is the sentence.

No standing access. Ever.

There is no permanent Sophicor seat inside your Workspace. No standing credential, no always-on connection, no support account waiting in your user list.

Our support commitment, in full:

  • Support will never ask you for client documents.
  • Diagnostics run on error codes, logs and structure — not on the contents of a return.
  • If an issue genuinely cannot be resolved that way, you decide whether to share a redacted sample, and you revoke access afterwards. That decision is always yours, and it is always temporary.

We would rather publish a policy we can keep than a promise that sounds better.

The part most vendors don't tell you.

Sophicor Forge performs the last mile — moving verified data into your tax software. You sign in to your own tax software with your own licence, and Forge does the typing.

Once the data is in your tax software, it lives wherever your tax software lives. If your firm runs Drake through a hosting provider, that hosting arrangement is between you and them — exactly as it is today, with or without us.

We are not going to tell you that your data "never leaves your walls" when part of your stack is somebody else's cloud. What we will tell you is precise:

Sophicor never receives your client data. Where your tax software keeps it is between you and your tax software.

What if Sophicor disappears?

It is a fair question to ask a young company, and most would rather you didn't. So here is the answer.

Every client record and every document is already in your Google Workspace. They were never anywhere else. If Sophicor ceased to exist tomorrow, you would lose the automation — and keep the entire archive, in place, in a system you already own and already pay for.

There is no export to request, no data-retrieval clause to invoke, no ninety-day window to worry about. That is not a policy we wrote. It is a consequence of where the software runs.

Two obligations worth knowing.

The following describes what these rules require and what Sophicor's architecture does about them. It is not legal or tax advice, and it is not a substitute for your own counsel. Current as of August 2026.

IRC §7216 — disclosure of tax return information

§7216 governs when a preparer may disclose or use a client's tax return information, and when written consent is required first. Disclosure to a third party generally requires consent obtained in advance and in a prescribed form. Because Sophicor's software runs inside your own Workspace and our systems do not receive your client data, using Sophicor does not itself put that information in a third party's hands. Your other arrangements — outsourced preparation, hosting, anything sent outside your firm — are assessed on their own facts.

The FTC Safeguards Rule

Tax preparers are treated as financial institutions under the Safeguards Rule and must maintain a written information security program — a designated qualified individual, a documented risk assessment, access controls, encryption, multi-factor authentication, and oversight of service providers. That last requirement is the one that gets harder with every vendor you add. Sophicor is designed to make it easier rather than heavier: fewer places your clients' data can be, and one fewer environment to assess.

If your firm's IT reviewer wants a written architecture summary for their file, ask and we will send one.

The other half of the truth.

A security page that only lists strengths is marketing. Here is the rest.

  • Sophicor holds no compliance certification. No SOC 2, no ISO 27001. We will say so plainly rather than imply otherwise, and we will tell you the day that changes.
  • We publish no accuracy percentage. Extraction is in active beta and improving weekly. A number we cannot substantiate is worth less than nothing on a page like this.
  • We are early. Sophicor is founder-built and shipping, not a decade-old platform, and you should weigh that.
  • Forge supports Drake Tax today. Support for further packages is on the roadmap and is not available yet.

Every one of those could have been left off this page. Firms that care about architecture tend to be the same firms that notice what a vendor chose not to mention.

Architecture is easier to show than describe.

Walk the interactive demo, or bring your firm's IT reviewer to a call and ask the hard version of every question on this page.