The sensitive work happens inside the firm.The external model starts from what the firm approved.
A model inside the firm’s own cloud account reads the documents, classifies the tax data, and runs the exact calculations. Only then is a payload assembled for Claude or ChatGPT.
Inside the firm
The external model
The payload is written, not edited.
The ordinary approach takes a client document and removes what it recognizes. Whatever it failed to recognize is still in there.
Proxara begins with an empty payload. Each fact is classified inside the firm, transformed under the firm’s policy, and added only if the system can account for it. There is no original document underneath, because the payload was never a document.
A model inside the firm does the reading.
Scanned K-1s, an 1120-S workpaper, a CP2000 notice, a spreadsheet with a hidden sheet. Something has to read the layout, decide which numbers are tax return information, and tie a Karbon requirement to an Outlook attachment. That is the sensitive part, so it runs on a model in the firm’s own cloud account, with no internet route and no credentials of its own.
The § 7216 argument rests on this placement.
This is everything the external model receives.
Approved facts and references that mean something only inside this piece of work. No client name, no address, no filename, no email address, no return figure. The form types are there because the model needs them to write the right sentence. The taxpayer they belong to is not. From this the model drafts the follow-up and selects the next action.
Requirements
Computed inside the firm
Approved next action
The calculation stays inside. The conclusion can travel.
A payload with every name and number taken out gives the model nothing to reason about. One with the figures perturbed is worse: fluent reasoning, wrong arithmetic.
The matching, the comparisons and the calculations all happen inside the firm, and the model receives their result. Threshold exceeded. Variance present. This document inconsistent with that one. Enough to draft and to plan. The figures stay where they were computed.
Prior-year comparison
Depreciation, TY2025248,300Depreciation, TY2024191,450Depreciation threshold
Computed248,300Threshold200,000Inside the firm
The external model
An unreadable page is not an empty page.
A scan the local model cannot read cleanly. An attachment in a format nothing supports. A value whose meaning is ambiguous. None of these becomes an approved fact, so none reaches the payload. The route narrows instead: the work stays local, drops that source, or stops and says so.
Stays local
Drops that source
Stops and says so
The system’s worst case is less useful, never less private.
The same client is a different reference tomorrow.
Acme ManufacturingInside the firm
The external model
Inside one piece of work [CLIENT_M42] holds, so the model can follow the same subject across Karbon, Outlook and the document store. When the work closes, it expires. The next piece of work issues a different reference, and the mapping between them never leaves the firm.
No client profile accumulates on the other side.
All of that happens before anything is sent.
Connecting the systems, matching records across them, and executing the approved action are the other three parts of the same boundary.
Proxara does not provide tax or legal advice. Firms should confirm the treatment of their own workflows with their counsel.





