For tax preparers & financial advisors
The FTC Safeguards Rule requires a WISP. Your PTIN renewal asks whether you have one.
Under the FTC Safeguards Rule (16 CFR §314.4), every tax preparer and financial firm that handles client financial data must have a written, maintained Written Information Security Program — and IRS Publication 4557 expects the same. It's now on the PTIN renewal checklist. Kovyr produces your WISP and the full packet, then keeps it current.
Your WISP packet
Written Information Security Program (WISP)
The document itself — mapped to all nine FTC Safeguards elements (16 CFR §314.4), with your current posture on each.
Incident Response Plan
Who does what if data is exposed, the IRS 24-hour and state/FTC notification clocks, and the response steps.
Qualified Individual Designation
Names the Qualified Individual accountable for the program and the reporting cadence to your senior officer.
Service-Provider Oversight Addendum
Your vendors, whether they touch client NPI, and ready-to-sign data-security clause language.
How it works
1 · Free scan
See what an attacker or an auditor can see from the outside — in seconds, no obligation.
2 · Compliance Assessment
We collect your answers, run the analysis, and deliver the full WISP packet. From $399.
3 · Trusted-Advisor Plan
Optional: we keep it current, help close the gaps, and monitor your exposure. $199/mo.
Start with a free look at your firm
Free, instant, and passive — we only read public information, the same as an attacker or insurance auditor would.
Ready for your WISP?
Book your Compliance Assessment — quoted per firm, from $399.
Book your assessmentKovyr produces compliance documentation reflecting your firm's information and our external observations. It is not legal advice, not a penetration test, and not a certification.