Trust & Security

ReliaHub Trust

Last Updated: August 15, 2026

You are being asked to put your clients' Social Security numbers into someone else's software. This page explains, in plain language, how ReliaHub protects them and what we will and will not do with them.

Everything here describes how ReliaHub works today. It is not a promise that nothing can ever go wrong — no software can honestly offer that, and our Terms of Service say so in the formal language lawyers require.

What ReliaHub is, and is Not

ReliaHub is a client workflow platform: intake, documents, appointments, follow-ups, and payment status. It is not tax preparation software. It does not prepare returns, transmit returns, or decide filing positions.

Using ReliaHub does not by itself satisfy your obligations under the FTC Safeguards Rule, IRS guidance, or state law. ReliaHub includes a guided Security Setup that walks you through the safeguards for your use of this platform and produces a record you can keep for your files. That is a genuinely useful document, and it is not a Written Information Security Plan for your whole practice. We will never tell you otherwise.

How Client Information is Protected

Social Security and Bank Numbers

Social Security numbers and bank routing and account numbers are encrypted with strong, industry-standard encryption (AES-256) before they are stored. They are held as unreadable ciphertext, and the key that opens them is never kept alongside them.

In the product these numbers stay masked. A preparer sees the last four digits until they choose to reveal the full number, and every reveal is recorded — who looked, at which client, and when.

One piece of practical advice: keep taxpayer numbers in the fields built for them. Those fields are encrypted. A free-text note is not the place for a Social Security number, in ReliaHub or in any other system.

Documents

Uploaded documents are held in private storage. There is no public link to a client document. Files are reachable only through short-lived links generated for a signed-in member of your practice, after ReliaHub has confirmed the document belongs to you.

Document-request links you send to clients are tied to a single client record, expire on their own, require the client to verify their email address or phone number before uploading, and can be revoked by you at any time.

Separation Between Practices

Each practice's information is separated from every other practice's at the database level, not by application code remembering to filter. A signed-in user reaches their own practice's records and nothing else.

Signing In

Two-factor authentication using an authenticator app is available to everyone with a ReliaHub login, and an account owner can require it for everyone in their workspace.

If you handle taxpayer information — and you do — turn it on.

What ReliaHub Staff Can and Cannot See

Most security pages are vague here, so we will be direct.

ReliaHub staff cannot:

  • open, preview, or download your clients' uploaded documents;
  • sign in as you or impersonate you — the product has no such feature;
  • read your clients' Social Security or bank numbers;
  • give themselves access to your workspace.

ReliaHub staff can ask you for temporary access to your client workflow information — names, stage, payment status — when you have reported a problem we cannot diagnose any other way. That request:

ends by itself;

  • must be approved by you, and only the account owner can approve it;
  • states a reason, written for you to read before you decide;
  • lasts only as long as you choose, up to a maximum of seven days, then
  • can be revoked by you at any moment;
  • appears in your account for you to see.

If nobody approves a request, nothing happens. Silence is a refusal.

Your Records

ReliaHub keeps an activity record covering changes to client records, data exports, document views and downloads, identity reveals, team and permission changes, and every support-access decision. The account owner can review it in Settings.

You can export your practice's records at any time while your account is active — client records, household members, cases, intake submissions, notes, tasks, payments, appointments, and email activity — along with your uploaded documents and your due-diligence log.

Uploaded documents follow a retention schedule. A document attached to a case is scheduled for deletion five years after that case is marked Completed; a document with no case, five years after upload. You are warned well before anything is removed — at one year, then 90, 60, 30, 15, and 7 days. Deletion is permanent.

Marking a case Completed is what starts that five-year clock, so it is a records decision rather than a way to tidy your dashboard. You remain responsible for keeping anything you are independently required to retain, and ReliaHub should not be the only place your records exist.

Where ReliaHub Operates

ReliaHub is operated by ReliaTax Group LLC, a United States company. The service is built for United States tax professionals and their clients, and is not offered outside the United States. How information is handled is described in our Privacy Policy.

Reporting a Security Problem

If you believe your account has been accessed without your permission, or you have found a weakness in ReliaHub, email security@myreliahub.com with what you saw and when. Please do not include Social Security numbers, bank details, or client documents in that message.

We will confirm we received it. If an incident affects your information, we will tell you by email, and by text message where appropriate.

About the Team

ReliaHub is built and operated by a small team. That has real advantages: decisions are quick, and nothing is buried in a bureaucracy. It has real limits too, and you should weigh both. When you write to us, a person who knows the product reads it.

Changes to This Page

This page describes ReliaHub as of the date at the top. When the product changes in a way that makes something here inaccurate, this page changes with it.

Related: Privacy Policy · Terms of Service · Data Processing Addendum