Data Security & WISP Compliance
IRS Publication 4557 & FTC Safeguards Standard
The Internal Revenue Service and the Security Summit mandate that professional tax preparers maintain a Written Information Security Plan (WISP) to protect client data against unauthorized access, identity theft, and ransomware.
Core Security Protocols
- Zero Unencrypted Email Policy: Taxpayers are instructed to never email returns or Social Security numbers. All transfers utilize our encrypted upload and client portal systems.
- Multi-Factor Authentication (MFA): Required across all tax preparation software, client document repositories, and internal workstation logins.
- 256-Bit SSL/TLS Encryption: Applied both in transit and at rest for all taxpayer data.
- Access Controls & Least Privilege: Access to client files is restricted solely to personnel directly responsible for preparing or reviewing the engagement.
