← All articles
accounting firm compliance stack IRS Circular 230 client records By BossBot Editorial Team · · Updated · 12 min read
Drafted with AI assistance under founder-led editorial direction. How our editorial team works.

Freshchat for Accounting Firms 2026: Where SOC 2 and Client Trust Meet

Freshchat for accounting firms 2026 — where SOC 2 and client trust meet

Accounting firms handle tax IDs and financial records. Freshchat is a helpdesk tool, not an accountant-client platform. The compliance surface differs.

In this article Hide ▲
  1. The compliance stack an accounting firm actually runs on
  2. What Freshchat is actually built for
  3. SOC 2 Type II — the vendor attestation that increasingly gates enterprise engagements
  4. The accounting-industry practice management platforms
  5. Where a firm can legitimately use general-purpose messaging
  6. The IRS-specific piece — Circular 230 client-record confidentiality
  7. The defensible 2026 accounting-firm client-communication stack

The compliance stack an accounting firm actually runs on

US accounting firms and CPA practices operate under overlapping compliance obligations that most 'chatbot for accountants' articles skip entirely. IRS Circular 230 (Regulations Governing Practice before the Internal Revenue Service): governs tax practitioner conduct, including client-record retention, confidentiality of client communications, and specific standards for information provided to clients and to the IRS. Gramm-Leach-Bliley Act and the FTC Safeguards Rule: firms that prepare tax returns for compensation and hold client non-public personal information (NPI) — Social Security numbers, income data, bank-account information — are financial institutions under GLBA and subject to the FTC Safeguards Rule requirements, which were significantly updated with 2023 amendments (Written Information Security Plan, designated qualified individual, multi-factor authentication on systems accessing NPI, encryption of NPI at rest and in transit, incident-response plan with FTC breach reporting in specific cases). AICPA professional standards and Code of Professional Conduct: client-record confidentiality obligations under Section 1.700, engagement-letter requirements, and specific rules on the use of third-party service providers with client information. State CPA board rules: additional confidentiality and record-retention requirements that vary by state (California Accountancy Act, Texas Public Accountancy Act, New York State Board for Public Accountancy rules). Any client-communication vendor a firm uses is inside this compliance surface — not around it.

What Freshchat is actually built for

Freshchat, part of the Freshworks product family (Freshdesk for helpdesk, Freshsales for CRM, Freshservice for IT service management), is positioned as a customer messaging solution for support and sales teams. Its centre of gravity is helpdesk-adjacent workflow: a shared inbox for inbound customer messages across web chat, email, SMS, WhatsApp, and Facebook Messenger; AI-driven bot for common customer-support queries; ticketing integration with Freshdesk; team-collaboration features. This is a legitimate and useful product for the customer profile it targets — a mid-market SaaS company's customer-support team, an e-commerce brand's post-purchase-support workflow, a subscription-service's cancellation-retention interactions. The mismatch with an accounting firm arises because the workflow is different. Accounting-client communication is not customer support (though it has support-adjacent moments). It is a professional-services engagement bound by confidentiality obligations, requiring a documented audit trail for every document exchanged, and running against a compliance stack that Freshchat's product surface was not calibrated to satisfy. The tool can be used by an accounting firm; it is not the right tool for the client-communication workflow specifically.

🎯 For accountants
Weekly notes on what's actually working for accounting firms.
Tax-season client-rush scripts, document-collection templates, tool comparisons — no fluff.

SOC 2 Type II — the vendor attestation that increasingly gates enterprise engagements

Mid-market and enterprise clients of an accounting firm — the client segments where fees justify a serious technology stack — increasingly require SOC 2 Type II attestation from vendors that touch their data. SOC 2 (System and Organization Controls 2) is an AICPA-developed audit framework that evaluates a service organisation's controls over five Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy). Type II attestations cover a period of operation (typically 6-12 months) rather than a point in time, providing evidence that the controls operated effectively over the period. For an accounting firm's client that requires SOC 2 from the firm's technology vendors, every vendor in the stack — practice management, document exchange, client portal, secure messaging, payment processor — should have current SOC 2 Type II reports available. Freshchat and Freshworks generally do publish SOC 2 reports and this is worth verifying against the vendor's current trust portal. The compliance question extends beyond the certification itself: does the vendor's controls scope map to the accounting-firm workflow (which handles NPI under GLBA and PII under state laws) or was it designed against a consumer-support workflow that does not carry the same regulatory weight?

The accounting-industry practice management platforms

Practice management platforms built for accounting firms bundle the client-communication surface with the compliance-relevant infrastructure firms need. TaxDome — cloud-native practice-management platform with client portal, secure document exchange, e-signature (compliant with the ESIGN Act), CRM, workflow automation, and secure messaging; widely adopted in the small-to-mid accounting firm segment. Karbon — practice-management platform with strong workflow, email triage, and client-communication features; UK and US market presence with SOC 2 attestation. Canopy — practice management with tax-specific features (IRS transcript pull, notice management, tax resolution workflow), client portal, secure messaging; targeted at tax-focused firms. Financial Cents — workflow and client-management platform with e-signature and secure client portal. Jetpack Workflow — task and workflow management with client-portal integration. Each of these was designed against the accounting-firm workflow specifically and holds the client-record confidentiality, document-retention, engagement-letter, and secure-message-exchange primitives as first-class features. The alternative — running a generic helpdesk tool for client communication and a separate spreadsheet for client management — is where accounting firms end up when they choose the wrong-shape tool early.

Where a firm can legitimately use general-purpose messaging

Nothing in the accounting compliance stack prohibits a firm from having a general-purpose messaging surface for non-sensitive communication. Legitimate use cases for a tool like Freshchat or an equivalent general messaging platform in an accounting firm: prospective-client intake at the top of the funnel where the initial exchange does not include any NPI or client-record content ('thanks for your interest — please schedule a discovery call at [link]'), general marketing outreach about services or educational content (tax-season reminders sent broadly, not client-specific), post-engagement satisfaction surveys where no client-specific financial data appears in the message body, industry-content newsletter management, receptionist-style front-line inbound triage that routes callers or messengers to the appropriate practice-management-platform-based communication channel. The compliance rule of thumb: any communication that identifies an existing client and touches their financial records, tax data, or NPI belongs in the practice-management platform's secure messaging surface; anything that does not can run on a general messaging tool. Getting this split right lets a firm have a legitimate marketing and intake presence without stepping into GLBA or Circular 230 exposure.

The IRS-specific piece — Circular 230 client-record confidentiality

Beyond GLBA and state professional standards, tax practitioners are additionally subject to IRS Circular 230, which governs practice before the IRS by attorneys, CPAs, enrolled agents, and other authorised representatives. Circular 230 sets specific requirements on client-record retention (§10.28), fees and reasonableness (§10.27), diligence in preparing returns (§10.22), and the standards for providing advice to clients (§10.37). It also incorporates by reference the general professional obligations of confidentiality and competence. Client communications that include tax-return content, engagement-letter terms, IRS notice responses, or planning advice fall squarely inside the Circular 230 record-retention and confidentiality scope. A messaging vendor that cannot produce a durable, audit-defensible record of client communications on request is a compliance risk regardless of how good its live-chat interface is. Practice-management platforms designed for accounting firms treat the message archive as a first-class object tied to the client engagement record; general-purpose messaging tools treat conversations as a support-ticketing artefact that ages out of easy retrieval. The difference matters when the IRS or a state board asks for the record.

The defensible 2026 accounting-firm client-communication stack

For a US accounting firm in 2026 with a client base including any income-tax, financial-statement, or advisory work, a defensible stack is layered: Practice-management platform as system of record — TaxDome, Karbon, Canopy, Financial Cents, or Jetpack Workflow — holding client records, engagement letters, document exchange, e-signature, secure messaging, and workflow. Payment processing — a vendor that signs a BAA-equivalent professional-services agreement and provides SOC 2 attestation (CPACharge, Melio for AP/AR, Stripe for card processing where the workflow accepts it). Marketing surface — Google Business Profile, LinkedIn firm page, ConvertKit or Mailchimp for newsletter distribution (with client-list management inside the practice-management platform, not in the marketing tool). General messaging for intake — a tool like Freshchat, Intercom, or equivalent for the pre-client, prospective-inquiry, or non-sensitive-communication surface, with a clear internal rule that as soon as the conversation touches client-specific financial content it moves into the practice-management platform's secure channel. Compliance — Written Information Security Plan per the 2023 FTC Safeguards Rule amendments, workforce training documented, incident response plan with breach-notification workflow, Circular 230 compliance including record retention, AICPA and state CPA board rule adherence. This stack is not the simplest possible; it is the honest one for a firm operating under the actual professional and regulatory standards US accounting practice requires.

Sources

Data + numbers referenced in this article are sourced from these public documents:

  1. FTC Standards for Safeguarding Customer Information (Safeguards Rule) — 2023 amendments
  2. AICPA Code of Professional Conduct — Section 1.700 confidentiality
  3. AICPA SOC 2 — Trust Services Criteria and Type II attestation
  4. TaxDome — accounting-firm practice-management platform
  5. Karbon — accounting practice management with workflow and client communication
  6. Canopy — tax-focused accounting practice management
  7. Freshchat — messaging product positioning inside Freshworks family

Frequently Asked Questions

For non-sensitive intake and pre-engagement communication, yes. For any communication that includes the client's tax data, financial statements, NPI, or engagement-specific content, no — the compliance surface (FTC Safeguards Rule for NPI, IRS Circular 230 record retention, AICPA client-confidentiality standards, state CPA board rules) requires a purpose-built accounting-industry practice-management platform's secure messaging channel. The split between what belongs in Freshchat and what belongs in the practice-management platform is the operational discipline that keeps a firm on the right side of the compliance line.
The selection depends on firm size, service mix (pure tax versus mixed advisory, audit and assurance work versus tax-only), and specific workflow needs. TaxDome and Karbon are the two most widely-adopted in the small-to-mid firm segment; Canopy is specifically strong for tax-focused firms with IRS notice-management needs; Financial Cents and Jetpack Workflow cover the workflow-heavy mid-market segment. A 30-90 day pilot with your actual workflow is more useful than a feature-comparison chart — the workflow fit and support responsiveness are the differentiators. Ask each vendor for the current SOC 2 Type II report before committing.
The 2023 amendments to the FTC's Standards for Safeguarding Customer Information, in force from 9 June 2023, added specific requirements for financial institutions under GLBA — including tax preparers and accounting firms holding client NPI. The requirements: designate a qualified individual to oversee the information security program, conduct a risk assessment, implement specific safeguards including multi-factor authentication on systems accessing NPI and encryption of NPI at rest and in transit, establish an incident response plan with reporting requirements, and ensure oversight of service providers. Verify current guidance directly against the FTC portal and consult a compliance attorney rather than relying on vendor-supplied assurances.
Only for non-sensitive content, and only if the firm has a documented policy that keeps NPI out of the WhatsApp channel. Meta's WhatsApp Business Platform does not offer a Business Associate Agreement (which is a HIPAA construct not directly applicable here) or an equivalent financial-services processing agreement that would satisfy an SOC 2 auditor's evaluation of vendor scope. A message on WhatsApp that says 'please check your client portal for details' is fine; a message that includes a Social Security number, tax-return line-item, or bank account is inside the GLBA-NPI scope and belongs in a compliant channel.
Your firm does not need to be SOC 2 certified itself in most cases — SOC 2 is designed for service organisations that process data on behalf of user entities. What you need is a vendor stack where each vendor that touches client data can produce a current SOC 2 Type II report on request. Larger clients — audit clients, enterprise advisory clients, financial-institution clients — will increasingly require this as a condition of engagement. Smaller firms serving only individual tax returns can defer the vendor SOC 2 question, but any firm growing into the mid-market segment should build the SOC-2-aware vendor stack early rather than migrate under audit pressure later.
📊
BossBot product

BossBot for Accountants & Bookkeepers

Product page with honest feature list, "not for you if" filter, and live demo for this vertical.

See /for/accounting →
What a conversation looks like
🤖
BossBot AI
● Online
Hi, I'm a sole trader and missed filing my self-assessment — am I in trouble?
Hi! Don't panic — penalties apply but we can minimise them. The sooner you file, the better. Can I take a few details to get started?
Yes please. I've got all my receipts, just haven't had time
Perfect — we just need receipts and bank statements and we'll do the rest. For urgent SA filing our fee is £150 flat. Want to book a quick call today or tomorrow?
Tomorrow morning if possible
10am tomorrow is free ✅ I'll book you in. You can send your documents beforehand so we're ready to go.
See full demo for your business →
🏢
See it in action
BossBot for Accounting firm compliance stack →
Features, demo, and pricing

The compliance stack first. The tool second.

BossBot supports non-sensitive messaging workflows for professional-services firms — with a clear split from the sensitive-client-record surface that belongs in an accounting-industry practice-management platform.

See where BossBot fits professional-services firms

Not ready to sign up yet? Try the free demo →

How did this land for you?
Tap what fits. Anonymous, one per browser.
✨ Recorded. Thanks for the vote.
📊 Accountant? Weekly notes on what other firms do. Free.