For tax preparers & financial advisors
The FTC Safeguards Rule requires a WISP. Your PTIN renewal asks whether you know it applies to you.
Under the FTC Safeguards Rule, every tax preparer and financial firm that handles client financial data must develop, implement, and maintain an information security program that is written down (16 CFR §314.3(a)) — and §314.2(i) defines that program as the safeguards you actually use. IRS Publication 4557 is the IRS explaining that rule to preparers; Form W-12 Line 11 asks you to confirm you're aware of it. Kovyr produces your WISP and the full packet from a real scan of your firm, then keeps it current.
Your WISP packet
Written Information Security Program (WISP)
The document itself — mapped to the elements of 16 CFR §314.4(a)–(j), with your current posture on each.
Incident Response Plan
Who does what if data is exposed, the notification duties that apply to you — including §314.4(j), which requires notice to the FTC within 30 days of a security event involving at least 500 consumers — and the response steps.
Qualified Individual Designation
Names the Qualified Individual accountable for the program and the reporting cadence to your senior officer.
Service-Provider Oversight Addendum
Your vendors, whether they touch client NPI, and ready-to-sign data-security clause language.
How it works
1 · Free scan
See what an attacker or an auditor can see from the outside — in seconds, no obligation.
2 · Compliance Assessment
We collect your answers, run the analysis, and deliver the full WISP packet. From $897, annual update $297/yr.
3 · Monitoring
Optional: recurring external monitoring with your documentation kept current — $1,497 with your assessment for the first year, then $99/mo. It is evidence toward §314.4(d)(1); it is not the “continuous monitoring” alternative in §314.4(d)(2).
Start with a free look at your firm
Free, instant, and passive — we only read public information, the same as an attacker or insurance auditor would.
One thing your security program probably doesn't cover.
Its vendor section assumes a company with a contract. A staff member pasting client information into a chatbot on a personal account isn't a vendor — so nothing in the program catches it. Our AI Readiness Assessment covers that gap — and credits in full toward the Compliance Assessment (from $897, or $1,497 with your first year of monitoring included) if you add it within 90 days.
Ready for your WISP?
Book your Compliance Assessment — quoted per firm, from $897.
Book your assessmentKovyr produces compliance documentation reflecting your firm's information and our external observations. It is not legal advice, not a penetration test, and not a certification. The IRS does not endorse or approve any vendor. Kovyr does not carry bound errors-and-omissions coverage and is not SOC 2 audited.