Accounting & financial · YamoHQ
Accounting, tax & financial

Keep the written security program the FTC expects.

For CPA, tax, bookkeeping and advisory firms. We run the technical controls the Safeguards Rule names and keep your program current.

What the rules expect

What you're expected to show

01A written information security program
02A qualified person responsible for it
03Multi-factor login for anyone accessing customer information
04Encryption of customer information
05Notice to the FTC within 30 days of a breach affecting 500 or more people
What we do

What we do about it

What's expected
What we do
What's expectedA written information security program
What we doWe document it and review it every year.
What's expectedA qualified person responsible for it
What we doWe support the person you name, with records of every review.
What's expectedMulti-factor login for anyone accessing customer information
What we doEnforced on every account.
What's expectedEncryption of customer information
What we doOn every device, in storage and in transit.
What's expectedNotice to the FTC within 30 days of a breach affecting 500 or more people
What we doAn incident plan with that deadline built in.

We run the technical controls and keep the records. We do not provide legal advice or certify compliance.

The rules

Who the Safeguards Rule covers

The FTC Safeguards Rule applies to tax preparers and many other financial firms. The IRS also expects tax professionals to keep a written security plan.

Start with a risk assessment

A fixed-fee review with a written report and plan. You keep both, whatever you decide next.

Book a risk assessment