Security and Use of Artificial Intelligence

shield and diagram depicting cybersecurity

Cybersecurity and Data Protection

At The John Ellis Company, protecting client information is a core professional obligation. We implement administrative, technical, and procedural safeguards designed to preserve the confidentiality, integrity, and appropriate use of client data, consistent with professional and regulatory standards applicable to Certified Public Accountants.

All email communications with clients are encrypted. We also operate exclusively under the “.cpa” domain, which is issued only to CPAs vetted by the American Institute of Certified Public Accountants (AICPA). This helps reduce the risk of email impersonation and phishing attacks. If you receive a message that appears to be from our firm but does not originate from a “.cpa” domain, it should be treated as a potential phishing or spear phishing attempt.

To further reduce risk, we do not transmit documents as email attachments. Instead, clients are provided access to a secure client portal for document exchange and collaboration. Our personnel receive regular cybersecurity training, and we perform periodic testing of our systems to identify and remediate vulnerabilities.

We also comply with the privacy and safeguarding requirements of 26 U.S.C. § 7216, which governs the protection and use of federal tax return information.

Email Impersonation Awareness

While the use of a “.cpa” domain helps reduce email impersonation risk, email clients may display sender names, logos, or images in ways that can be misleading. In some cases, malicious actors may attempt to impersonate trusted senders by manipulating how an email appears in a recipient’s inbox, even when the underlying email address is not legitimate.

Clients are encouraged to review the full sender address of unexpected or unusual messages and to use standard email security practices on their own systems. If you ever have questions about the authenticity of a message claiming to be from The John Ellis Company, we encourage direct verification using known contact information.

While no system can guarantee absolute security, our controls are designed to protect client information in a manner consistent with applicable professional, ethical, and regulatory responsibilities.

Payment Card Security

The John Ellis Company does not store, process, or transmit payment card information on its own systems. All payment card transactions are handled entirely by PCI DSS compliant third party payment processors.

We maintain internal policies and procedures designed to support applicable data security and confidentiality standards. Documentation related to payment security and compliance is maintained internally and is available to clients upon reasonable request, subject to appropriate confidentiality safeguards.

Our Use of Artificial Intelligence

The John Ellis Company may use artificial intelligence (AI) tools to support certain aspects of our professional services, such as drafting, research, data organization, and workflow efficiency. These tools are used to assist our professionals — they do not replace professional judgment, experience, or responsibility.

All client work is reviewed and finalized by qualified professionals, and the firm remains fully responsible for the accuracy, integrity, and compliance of its services.

Artificial intelligence is not used to independently generate tax positions, provide final tax advice, make compliance determinations, or replace human professional judgment.

We do not input client confidential information into public AI tools. Any AI solutions used by the firm are subject to confidentiality, security, and vendor oversight standards designed to preserve client data ownership and privacy.

Our use of artificial intelligence aligns with:

  • The AICPA Code of Professional Conduct
  • Applicable independence, objectivity, and due care standards
  • Relevant regulatory and professional guidance governing CPA firms

Clients with questions or concerns regarding our cybersecurity practices or use of artificial intelligence are encouraged to contact the firm’s management team.

Informational Notice

This page is provided for informational purposes only and does not modify, replace, or supersede the terms of any client engagement, engagement letter, or agreement with The John Ellis Company.