Private self-hosted LLM

Why Taxpartna uses a private self-hosted LLM for sensitive tax documents

Tax returns and accounting workpapers contain some of the most sensitive information held by an accounting firm.

They can include names, addresses, tax file numbers, bank details, dates of birth, salaries, investment information, business results, trust distributions, loan balances and details about related parties. In many cases, a single tax file provides a detailed financial picture of an individual, family or private business group.

This information should not be entered into a publicly available generative AI tool without a clear understanding of how the data will be processed, retained, accessed and used.

Taxpartna uses a private self-hosted large language model environment because sensitive tax quality assurance requires a higher level of control than a public AI chatbot is designed to provide.

The difference is not simply where the model runs. It is about controlling the complete journey of the document from upload and analysis through to deletion.

What is a public LLM?

A public large language model is generally accessed through a publicly available chatbot, website or application operated by an external provider.

These services are designed for broad use. A user enters a question, text or document and the provider processes that information using its own systems.

The exact treatment of submitted data depends on the provider, product, account type, settings and contractual terms. Some consumer services may retain conversations or use submitted content to improve their products. Some enterprise services provide stronger contractual protections, controlled retention and commitments not to train models on customer data.

For an accounting firm, the problem is that the privacy and security position cannot be assumed from the brand name alone. The firm must understand the specific service being used and the terms that apply to that service.

The Office of the Australian Information Commissioner recommends that organisations do not enter personal information, particularly sensitive information, into publicly available generative AI tools because of the significant and complex privacy risks involved.

What is a private self-hosted LLM?

A private self-hosted LLM is deployed within infrastructure controlled for a particular organisation or application rather than accessed through a general public chatbot.

The infrastructure may be located on dedicated servers, within a private cloud environment or through another controlled hosting arrangement. What matters is that the organisation operating the application controls the model deployment, data pathways, access permissions, retention settings and supporting systems.

A private self-hosted model can be configured so that submitted documents are used only to perform the requested analysis. The content does not need to be sent to a public LLM provider or used to train a general model.

Self-hosting does not automatically make an AI system secure. The operator must still implement strong access controls, encryption, monitoring, software updates, incident response and secure deletion. The benefit is that these controls can be designed around the specific risks of the application.

Private self-hosted LLM compared with a public AI tool

AreaPublicly available AI toolPrivate self-hosted LLM
Data processingDocuments are processed within the external provider's serviceDocuments are processed within the controlled application environment
Data useDepends on the provider, product, settings and termsCan be restricted to the requested analysis only
Model trainingMay vary between consumer and enterprise servicesClient documents can be excluded from model training by design
RetentionControlled by the provider's product settings and policiesRetention can be configured for the application and business purpose
AccessManaged through the external provider's systemsAccess can be limited to authorised application users and administrators
AuditabilityLogging and audit information depend on the providerLogging can be designed around the firm's review and security requirements
Model changesThe provider may change models, features or behaviourModel versions and updates can be tested before deployment
IntegrationDesigned for broad, general useCan be integrated into a specific tax quality assurance workflow
Security responsibilityShared with and substantially dependent on the external providerGreater operator control, with greater responsibility for secure operation

This comparison relates primarily to publicly available consumer AI tools. Enterprise AI platforms may provide additional contractual, privacy and security protections and should be assessed on their individual terms.

Greater control over sensitive client information

The main benefit of a private self-hosted LLM is control.

An accounting firm should know what happens to a client document after it is uploaded. That includes where the file is stored, which systems process it, who can access it, whether a copy is retained and when it is deleted.

A private AI environment allows these decisions to be built into the product architecture rather than relying solely on the standard settings of a public chatbot.

For Taxpartna, documents are provided for a specific purpose: to perform tax quality assurance checks and identify matters for professional review. The system can be designed to limit processing to that purpose and minimise unnecessary handling of the information.

This supports a privacy by design approach, where privacy and security controls are considered when the system is developed rather than added after sensitive information has already been collected.

Client documents are not prompts for a public chatbot

Using a public AI chatbot for tax work can appear convenient. A user uploads a document and asks the model to find errors or provide a summary.

The difficulty is that the accountant may not know the full data flow behind that interaction. The document may pass through systems located in other jurisdictions, be retained in conversation history or become accessible through administrative or support processes governed by the provider's terms.

There is also a risk that staff use different tools, accounts and privacy settings. This creates inconsistent practices across the firm and makes it difficult to confirm what information has been disclosed.

Taxpartna provides a controlled alternative. Staff use an approved platform developed for tax quality assurance rather than deciding individually which general AI tool to use for client documents.

Reduced risk of client data being used for model training

Accounting firms should not assume that data entered into an AI service will never be used to improve that service.

The position depends on the specific product and contractual terms. Consumer products, free services and experimental tools may have different rules from enterprise offerings.

A private self-hosted LLM can be operated without using client documents to train or fine-tune the model. The documents can be processed for the immediate review and then removed in accordance with the application's retention settings.

This separation is important. A client provides financial information to their accountant for taxation and professional services. The information should not become training material for an unrelated general-purpose system without an appropriate legal basis, transparency and authority.

Configurable data retention and secure deletion

Data minimisation means collecting and retaining only what is reasonably required for the intended purpose.

Public AI services may offer history settings or deletion functions, but the available controls vary. Deleting a conversation from the user interface may not always explain what remains in backups, security logs or other provider systems.

In a private self-hosted environment, retention can be designed around the tax review workflow. Temporary source documents can be removed after processing while the firm retains the professional review output it requires for its engagement file.

The system operator must still verify that deletion applies across storage locations, temporary files, backups and logs. A clear retention design is more reliable than relying on staff to remember to delete individual public chatbot conversations.

Stronger access controls

Sensitive tax documents should only be available to people who require access for their work.

A private platform can apply role-based access, multi-factor authentication and firm-level user management. Access can be linked to the accounting firm's approved users rather than personal or unmanaged public AI accounts.

This gives the firm greater visibility over:

  • Who can submit client documents
  • Who can view review results
  • Which firm or team owns the file
  • When access was granted or removed
  • Whether security controls such as multi-factor authentication are operating

Access control is particularly important for firms with multiple offices, remote staff, contractors or offshore preparation teams.

A controlled model and review process

Public LLM providers regularly update their models. Updates can improve performance, but they can also change how the model interprets instructions, presents results or responds to the same information.

A private self-hosted deployment provides greater control over model versions and system changes. Updates can be evaluated before they are introduced into the tax quality assurance process.

Taxpartna also applies its own structured checks and workflow around the model. The objective is not to ask a general chatbot an open-ended question. The objective is to perform defined tax QA procedures and present the results in a consistent format for professional review.

This produces a more controlled outcome than an employee entering an improvised prompt into a public AI tool.

Better alignment with accounting firm governance

Introducing AI into an accounting practice should be a firm decision supported by policies, training and approved systems.

If staff use public AI tools independently, the firm may struggle to identify which services are being used, what documents have been uploaded and whether the relevant privacy settings were applied.

A private tax QA platform allows the firm to establish one approved process. Its policies can specify:

  • Which documents may be submitted
  • Which users are authorised
  • The purpose for which the system may be used
  • How review results must be assessed
  • What evidence is retained on the engagement file
  • How privacy or security incidents are reported
  • When client information is deleted

This supports consistent governance and reduces the risk of unapproved shadow AI use within the practice.

Privacy considerations for Australian accounting firms

Australian accounting firms may hold personal information and sensitive information covered by the Privacy Act 1988 and the Australian Privacy Principles.

The use of an AI system can involve collection, use and disclosure of personal information. Firms should consider whether the proposed processing is consistent with the purpose for which the information was collected and with their privacy notices, client authorities and professional confidentiality obligations.

The OAIC recommends a cautious approach to the use of commercially available AI products and a privacy by design approach when developing or adapting AI systems.

A private self-hosted environment can support that approach by reducing unnecessary external disclosure and enabling more precise controls. It does not remove the need for privacy assessment, appropriate contracts, security controls, data governance and transparent information for clients.

Security responsibilities still apply

Private hosting transfers greater control to the system operator, but it also creates greater responsibility.

A securely operated private LLM environment should address:

  • Encryption in transit and at rest
  • Multi-factor authentication
  • Role-based access controls
  • Secure infrastructure configuration
  • Vulnerability and software patch management
  • Model and software supply chain risks
  • Security logging and monitoring
  • Separation of customer information
  • Backup and deletion processes
  • Incident detection and response
  • Testing before model or system updates

The Australian Cyber Security Centre advises organisations to consider security throughout the AI system lifecycle, whether the system is self-hosted or provided by a third party.

The correct comparison is therefore not public AI versus automatically secure private AI. It is a general-purpose external service with limited customer control compared with a purpose-built private environment operated under documented security controls.

Why this matters for tax quality assurance

Tax quality assurance requires access to detailed source documents. A useful review may involve tax returns, financial statements, workpapers, trust resolutions, loan agreements and other records that should not be exposed beyond the engagement without a clear need.

Taxpartna was designed so accounting firms do not have to choose between detailed automated review and control over client information.

Its private self-hosted model environment supports:

  • Purpose-limited processing of tax documents
  • No submission of client files to a public LLM chatbot
  • Controlled access for authorised users
  • Consistent tax review procedures
  • Configurable data retention
  • Structured outputs for professional assessment
  • Human oversight by the registered tax practitioner

The model performs detailed analysis within the controlled workflow. The accountant remains responsible for reviewing the results and making every professional decision.

Private AI built for Australian tax practitioners

General AI tools are designed to answer questions across almost every subject. Taxpartna is designed for one professional purpose: assisting Australian tax practitioners with tax file quality assurance.

The platform combines a private self-hosted LLM environment with structured tax checks, secure document handling and practitioner oversight.

This gives accounting firms access to advanced document analysis without requiring staff to upload sensitive client files to publicly available AI tools.

For a profession built on confidentiality and trust, that control matters.

See secure tax QA in practice

Discover how Taxpartna can review sensitive tax documents within a controlled private AI environment.

Join the Taxpartna beta or request a demonstration of the document review and security process.

Frequently asked questions

A private self-hosted LLM is a large language model deployed within infrastructure controlled for a particular organisation or application. The operator controls the deployment, data pathways, access settings, retention and model updates rather than relying on a general public chatbot.

Authoritative references

Taxpartna performs automated tax quality assurance checks to support professional review. It does not replace the judgment of a registered tax practitioner, who remains responsible for reviewing results and making all professional decisions.