TAX MASTERSYOUR KEY TO A BETTER RETURN
  • Home
  • Services
  • Meet Melanie
  • University
  • Tax Docs
  • WISP
  • Operating
  • Contact
LEGAL · SECURITY · WISP

Security Policy

Tax Masters' Written Information Security Plan (WISP) — the administrative, technical, and physical safeguards we use to protect every piece of data you entrust to us.

Effective Date
January 1, 2026
Reviewed
Annually

Tax Masters maintains a documented Written Information Security Plan, often called a WISP, in accordance with the Gramm-Leach-Bliley Act, the Federal Trade Commission Safeguards Rule (16 CFR Part 314), and IRS Publication 4557 (Safeguarding Taxpayer Data). The plan is a living document — reviewed annually, updated as our technology and the threat landscape evolve, and signed off by Melanie Romero as our designated Information Security Coordinator.

This page summarizes the safeguards in plain language so clients, partners, and regulators understand how seriously we take the protection of taxpayer information.

Federal Law
GLBA Compliance Gramm-Leach-Bliley Act financial data privacy standards.
Regulation
FTC Safeguards Rule 16 CFR Part 314 administrative, technical, physical safeguards.
IRS Standard
Publication 4557 Safeguarding Taxpayer Data — preparer obligations.
IRS Framework
Publication 5708 Sample WISP framework for tax professionals.

1. Designated Security Coordinator

Tax Masters maintains a Designated Information Security Coordinator responsible for implementing this plan, training employees and Tax Partners, evaluating service providers, supervising security audits, and responding to incidents. The Coordinator is identified internally and can be reached for security matters via the contact information at the bottom of this page.

2. Scope & Covered Information

This Security Policy covers all "non-public personal information" we handle, including but not limited to:

  • Taxpayer name, address, phone, email, Social Security Number, ITIN, driver's license, passport number.
  • Tax documents (W-2, 1099, 1098, K-1, prior-year returns, supporting receipts).
  • Bank account and routing numbers used for refund deposit or balance-due payment.
  • Employer Identification Numbers, business records, payroll data, accounting files.
  • Tax Partner registration information, including PTIN, EFIN, training records.
  • Any other client or partner information processed in physical or digital form.

3. Risk Assessment

We conduct a written risk assessment at least once a year. The assessment evaluates:

  • Internal risks — employee access, mistaken disclosure, weak passwords, lost devices.
  • External risks — phishing, malware, ransomware, unauthorized network access, social engineering, mailroom interception.
  • Vendor risks — exposure introduced by tax software providers, payment processors, document upload tools, and email providers.
  • Physical risks — break-in, fire, water damage, theft of paper records or hardware.

For each identified risk, we document the safeguard we apply and the residual risk we accept.

4. Administrative Safeguards

Written Policies

Every Tax Masters team member signs the Security Policy, Confidentiality Agreement, and acknowledges this WISP. Policies cover acceptable use, passwords, remote work, document handling, and incident reporting.

Annual Training

All team members receive security training at onboarding and annual refreshers. Topics include phishing, social engineering, secure document handling, password hygiene, and IRS data-theft red flags.

Role-Based Access

Access to client data is limited to people who need it. New team members get access only to what their role requires; access is revoked the same day a team member's relationship with Tax Masters ends.

Background Checks

Anyone handling taxpayer data is screened before being granted access. Tax Partner applicants are vetted through PTIN verification, prior-employment references, and review of training completion.

5. Technical Safeguards

Encryption

All client data encrypted in transit (TLS 1.2+) and at rest (AES-256). Email containing tax docs is sent only through encrypted portals or secure-upload links — never as plain attachments.

MFA Everywhere

Multi-factor authentication is enforced on every professional tool: tax software, client portal, email, payment processing, file storage, and IRS e-Services. Strong passwords, rotated per industry guidance.

Endpoint Security

Every device runs current antivirus, has the OS patched on schedule, uses a firewall, and auto-locks after a short period of inactivity.

Network Security

Business-class firewall with intrusion detection. Public/guest networks are never used to access tax systems. Remote access goes through encrypted VPN with MFA.

Daily Backups

Client data backed up daily to encrypted offsite storage. Backups tested regularly. In a disaster we can rebuild from the most recent backup within a documented recovery window.

Activity Logging

All access to client data is logged. Login activity, file access, and admin changes are recorded for security review and forensic analysis if a security event ever occurs.

6. Physical Safeguards

Locked Storage

Paper documents stored in locked cabinets or a locked office during business hours and after.

Screen Privacy

Workstations positioned so screens aren't visible to clients or visitors. Auto-lock on inactivity.

Alarmed Office

Office is alarmed. Physical keys are tracked and reissued whenever access changes.

Secure Disposal

Expired documents shredded with cross-cut shredder or bonded service. Hardware securely wiped or destroyed at end of life.

7. Vendor & Service-Provider Management

Every third party that touches client data — tax software, payment processor, email host, scheduling platform, form host, document upload provider — is evaluated against the same security standards we hold ourselves to. We require a written agreement that the vendor will:

  • Protect our data with safeguards no weaker than ours.
  • Use the data only to deliver the services we contracted for.
  • Notify us promptly of any suspected or confirmed data incident.
  • Return or destroy data at the end of the contract.

8. Incident Response Plan

If we suspect or detect a data incident — lost device, unauthorized access, phishing compromise, software breach, or any other security event — we follow a documented response plan:

  • Contain — isolate the affected system or account immediately.
  • Assess — determine what data was involved, what windows of time, and which clients are affected.
  • Notify — inform affected clients without unreasonable delay, and notify the IRS Stakeholder Liaison and state authorities where required.
  • Mitigate — provide credit-monitoring or identity-protection support where appropriate, reset compromised credentials, patch the underlying weakness.
  • Document — record the timeline, root cause, and corrective actions in our incident log.
  • Review — update this WISP if the incident reveals a gap in our safeguards.

9. Recordkeeping & Destruction

Client records are retained for a minimum of seven (7) years following the filing date in accordance with IRS recordkeeping guidance, and longer where applicable law requires. At the end of the retention period, records are destroyed by secure shredding (paper) or cryptographic deletion (digital).

10. Annual Review & Updates

This Security Policy is reviewed at least once every twelve (12) months by the Information Security Coordinator. The review covers changes in technology, changes in our client mix, new regulatory guidance, lessons learned from any incidents, and feedback from clients and team members. Material updates are communicated to the team and posted to this page with a refreshed "Last Reviewed" date.

11. Contact & Reporting

To report a suspected security incident, ask a question about our safeguards, or request a copy of the full internal WISP for verification purposes (lender, attorney, regulator) — reach the Tax Masters Compliance team:

Phone
(888) 516-8802
Compliance Email
compliance@taxmastersatwork.com
Office
Miramar, FL 33023

This page summarizes Tax Masters' Written Information Security Plan for the public. The complete internal WISP, including specific tools, vendor names, and operational detail, is maintained as a confidential business document and disclosed only on a need-to-know basis. Tax Masters reserves all rights to this policy.

Tax Masters

Your Key to a Better Return. Tax preparation, bookkeeping, and business management for individuals and small businesses.

Quick Links

  • Services
  • Meet Melanie
  • Tax Master University
  • Contact

Policies

  • Privacy Policy
  • Security Policy
  • Operating Procedure
Copyright © Tax Masters. All Rights Reserved.  |  taxmastersatwork.com