Multi-factor authentication, enforced
On every account that reaches client data, with a report showing it, so the answer on a form is something you can stand behind.
Accounting and tax
Your firm holds client tax data, so the FTC Safeguards Rule applies to you and the IRS expects a written information security plan, a WISP. We run the IT that lets you say yes to both.
What applies to you
The FTC Safeguards Rule names tax preparation firms directly, whatever their size. It expects multi-factor authentication, encryption, control over who can reach client data, and oversight of the providers who hold it. IRS Publication 4557 adds the WISP, and PTIN renewal asks whether you know one is required. This is what we do about each.
On every account that reaches client data, with a report showing it, so the answer on a form is something you can stand behind.
Enforced and evidenced on managed laptops and desktops, so a lost device is a documented non-event.
Documentation, logging, and a monthly security report, so the plan describes what you actually run rather than what a template assumed.
Where the data sits
Your tax software is hosted and hardened. The W-2 photographed and emailed, the brokerage statement attached to a thread, the portal invitation with a Social Security number in the body: those sit in mail and cloud storage long before they reach the software. Every plan watches your Microsoft 365 accounts around the clock, because that is where an accounting firm gets attacked.
Which plan
Protect+ for a firm with a WISP to keep and a Safeguards program to show: it adds the documented controls, retained logs, and awareness training those documents describe. Protect where you need managed devices without the compliance layer. Either way it supports your program; it is not a certification. Every plan rate and the add-ons most businesses need are on the pricing page.
Frequently asked
Yes. Section 314.2(h) names tax preparation firms directly, and a sole practitioner is covered on the same terms as a large practice. Size changes which parts apply, not whether it applies: multi-factor authentication, encryption, access controls and oversight of your providers apply at any size.
A written information security plan. IRS Publication 4557 sets out what safeguarding taxpayer data requires, and the WISP records how your firm does it. Anyone with a PTIN who handles client tax data needs one, and PTIN renewal on Form W-12 asks you to confirm you know that.
Not the software itself; its vendor does that. We manage everything it runs on: the computers, the Microsoft 365 accounts and mail, the network, and the backups around ProSeries, Lacerte, Drake, UltraTax and QuickBooks.
No. The rule allows a service provider to hold the role on conditions, but our position is that the accountability belongs inside the firm. We implement and document the technical safeguards, and we answer the oversight questions about ourselves.
A thirty-minute call where we go through what you run and what is not working. We reply within one business day, and there is no obligation.
Schedule an IT assessment