WagerBooks is a gambling session report and tax-compliance support service, built to help gamblers, CPA firms, and tax professionals produce accurate, defensible W-2G and session-level records. Our delivery model is designed around confidentiality, restricted access, controlled technology use, and human-reviewed work.
Where we support a CPA or tax firm rather than an individual client directly, we operate under that firm’s authorization and direction, and the firm retains ownership of the client relationship and final professional responsibility for the work delivered.
Because producing a session report often requires access to your gambling platform accounts (including platforms such as BetMGM, DraftKings, FanDuel, BetRivers, Caesars, and PokerStars), we treat login credentials as the most sensitive category of information we handle:
Credentials are used exclusively for data extraction during the active order window, by the specific team member assigned to your engagement. No login information is stored in any permanent system after your report is delivered. All credential handling takes place through encrypted, access-controlled channels. We recommend resetting your platform password after your report has been received, and a password-reset checklist is provided with every completed order. Credential sharing between team members outside approved access procedures is prohibited.
Opening and closing balance screenshots. As an additional safeguard, we capture a screenshot of your account balance (if any) at the moment we begin work on the platform, and a second screenshot at the moment we close out and log off. This gives both you and us a verifiable, timestamped record that the balance on your account was unchanged before and after our access, and it is the first thing we check if any discrepancy is ever raised.
No disclosure of our identity to platform customer support. If we ever need to reach a gambling platform’s customer support to resolve a technical issue while accessing your account (for example, a locked login or a report export issue), we interact with support as the account holder and do not reveal that a third party (WagerBooks) is accessing the account. Any such contact is limited strictly to the technical matter at hand.
No changes to account settings. We do not change your password, contact details, linked payment methods, or any other account settings. We do not place bets, withdraw funds, or interact with the platform beyond what is required to retrieve the data needed for your report.
One login, one purpose. Each login session is used solely to retrieve the records needed for your report, transaction history, session data, and W-2G information. We do not browse, use, or retain access to your account beyond that purpose, and access is closed out as soon as the required data has been extracted.
Access to client information is limited to personnel assigned to the relevant engagement or order. Team members use individual accounts, and client folders and workspaces are segregated so personnel outside the assigned engagement do not have routine access. Access is granted and removed by authorized managers, and permissions are reviewed periodically, including on a monthly basis. Administrative privileges are restricted to authorized personnel, and multi-factor authentication is used across company systems.
Client work is performed on company-issued, encrypted computers with endpoint security and automatic screen-lock controls. Personal laptops and personal devices are not permitted for client work. Team members cannot install unauthorized software or browser extensions, and USB and removable storage devices are restricted. Photographing or taking unauthorized screenshots of client information is prohibited. Any locally downloaded working files (such as W-2G forms, transaction exports, or extracted platform data) are removed once the relevant report is complete. Client information is not synchronized to personal cloud-storage accounts.
Each client’s information is treated as confidential and kept separate from other engagements. Information belonging to one client or firm is never made available to, or used as working material for, another.
Platform credentials are deleted immediately upon order completion. Raw gambling platform data we extract, along with any W-2G forms, transaction exports, or other records you share with us directly, is deleted after your report is confirmed received. Contact and billing information is retained only as long as reasonably necessary for accounting, legal, and support purposes. Completed session reports are not retained on our systems beyond 30 days from delivery, unless you have a CPA firm agreement with ongoing reporting requirements. Client-requested deletion can be supported, subject to legal, contractual, and backup requirements, and confirmation of deletion can be provided where requested.
Every session report passes through a structured review process before delivery, so no single person’s work goes out unchecked: a Preparer extracts and classifies session-level data based on the platform records and supporting documents provided; a Reviewer independently checks the preparer’s work against source documents (W-2G forms, transaction exports, platform data) for accuracy and completeness; and a Closer gives final confirmation before the report is finalized and delivered.
Team members handling client financial or gambling data undergo background checks before being granted access to client data. Every team member signs a confidentiality agreement covering client and firm information, with obligations that continue beyond the end of employment. Team members receive information-security, privacy, and phishing-awareness training, and are specifically instructed that platform passwords and credentials are used only for extraction, never stored long-term.
Access is disabled immediately when a team member leaves or is reassigned. Credentials are revoked or rotated, company equipment is recovered, and access changes are documented.
We maintain an incident-response process covering events such as suspected credential compromise, unauthorized access, or accidental disclosure. Team members are trained to escalate suspected security incidents immediately for investigation. Where a confirmed security event affects your information, we will notify you promptly and in accordance with applicable law.
Data in transit is protected with encryption (HTTPS/TLS). Data at rest is protected using industry-standard encryption appropriate to its sensitivity. We apply access controls, monitoring, and periodic review of our internal data-handling practices. No method of electronic transmission or storage is 100% secure, but we apply every reasonable measure to protect your information.
We may use automation and AI-assisted tools to speed up parts of our workflow, such as data extraction and preliminary transaction classification. These tools do not replace human review, every report passes through our Preparer → Reviewer → Closer process before it reaches you. Sensitive information such as platform credentials, passwords, and government ID numbers is never entered into general-purpose or unapproved AI tools. See our AI Usage Policy for full details.
We use selected, reputable technology providers for hosting, payment processing, and service delivery, and require appropriate confidentiality and data-handling commitments from them. Where relevant for a CPA or tax firm’s own vendor due diligence, information about our material technology providers can be provided on request.
We maintain internal security policies and operational controls. We do not currently represent WagerBooks as SOC 2 examined or ISO/IEC 27001 certified unless and until the applicable independent assessment has been completed. We continue to evaluate additional independent assurance frameworks as our client and enterprise requirements evolve.
CPA firms and tax professionals may conduct reasonable vendor-security due diligence before referring clients to us or engaging our services. We can support security questionnaires and provide appropriate information about our security policies and subprocessors, just raise this during onboarding.
If you believe you have discovered a security vulnerability, or have concerns about the security of your data, please contact us so we can investigate promptly.
Email: info@wagerbooks.com
This page describes our operational security practices and is provided for general information. It does not constitute a warranty or contractual commitment; specific security or compliance requirements can be addressed as part of an engagement or service agreement.