Tax Masters' Written Information Security Plan (WISP) — the administrative, technical, and physical safeguards we use to protect every piece of data you entrust to us.
Tax Masters maintains a documented Written Information Security Plan, often called a WISP, in accordance with the Gramm-Leach-Bliley Act, the Federal Trade Commission Safeguards Rule (16 CFR Part 314), and IRS Publication 4557 (Safeguarding Taxpayer Data). The plan is a living document — reviewed annually, updated as our technology and the threat landscape evolve, and signed off by Melanie Romero as our designated Information Security Coordinator.
This page summarizes the safeguards in plain language so clients, partners, and regulators understand how seriously we take the protection of taxpayer information.
Tax Masters maintains a Designated Information Security Coordinator responsible for implementing this plan, training employees and Tax Partners, evaluating service providers, supervising security audits, and responding to incidents. The Coordinator is identified internally and can be reached for security matters via the contact information at the bottom of this page.
This Security Policy covers all "non-public personal information" we handle, including but not limited to:
We conduct a written risk assessment at least once a year. The assessment evaluates:
For each identified risk, we document the safeguard we apply and the residual risk we accept.
Every Tax Masters team member signs the Security Policy, Confidentiality Agreement, and acknowledges this WISP. Policies cover acceptable use, passwords, remote work, document handling, and incident reporting.
All team members receive security training at onboarding and annual refreshers. Topics include phishing, social engineering, secure document handling, password hygiene, and IRS data-theft red flags.
Access to client data is limited to people who need it. New team members get access only to what their role requires; access is revoked the same day a team member's relationship with Tax Masters ends.
Anyone handling taxpayer data is screened before being granted access. Tax Partner applicants are vetted through PTIN verification, prior-employment references, and review of training completion.
All client data encrypted in transit (TLS 1.2+) and at rest (AES-256). Email containing tax docs is sent only through encrypted portals or secure-upload links — never as plain attachments.
Multi-factor authentication is enforced on every professional tool: tax software, client portal, email, payment processing, file storage, and IRS e-Services. Strong passwords, rotated per industry guidance.
Every device runs current antivirus, has the OS patched on schedule, uses a firewall, and auto-locks after a short period of inactivity.
Business-class firewall with intrusion detection. Public/guest networks are never used to access tax systems. Remote access goes through encrypted VPN with MFA.
Client data backed up daily to encrypted offsite storage. Backups tested regularly. In a disaster we can rebuild from the most recent backup within a documented recovery window.
All access to client data is logged. Login activity, file access, and admin changes are recorded for security review and forensic analysis if a security event ever occurs.
Paper documents stored in locked cabinets or a locked office during business hours and after.
Workstations positioned so screens aren't visible to clients or visitors. Auto-lock on inactivity.
Office is alarmed. Physical keys are tracked and reissued whenever access changes.
Expired documents shredded with cross-cut shredder or bonded service. Hardware securely wiped or destroyed at end of life.
Every third party that touches client data — tax software, payment processor, email host, scheduling platform, form host, document upload provider — is evaluated against the same security standards we hold ourselves to. We require a written agreement that the vendor will:
If we suspect or detect a data incident — lost device, unauthorized access, phishing compromise, software breach, or any other security event — we follow a documented response plan:
Client records are retained for a minimum of seven (7) years following the filing date in accordance with IRS recordkeeping guidance, and longer where applicable law requires. At the end of the retention period, records are destroyed by secure shredding (paper) or cryptographic deletion (digital).
This Security Policy is reviewed at least once every twelve (12) months by the Information Security Coordinator. The review covers changes in technology, changes in our client mix, new regulatory guidance, lessons learned from any incidents, and feedback from clients and team members. Material updates are communicated to the team and posted to this page with a refreshed "Last Reviewed" date.
To report a suspected security incident, ask a question about our safeguards, or request a copy of the full internal WISP for verification purposes (lender, attorney, regulator) — reach the Tax Masters Compliance team:
This page summarizes Tax Masters' Written Information Security Plan for the public. The complete internal WISP, including specific tools, vendor names, and operational detail, is maintained as a confidential business document and disclosed only on a need-to-know basis. Tax Masters reserves all rights to this policy.