Our security program
We are a service provider. You are required to check on us.
16 CFR 314.4(f) and 201 CMR 17.03(2)(f) both require you to select service providers capable of maintaining appropriate safeguards and to impose those safeguards by contract. That includes us. This page exists so you can do that diligence properly, and so it can go straight into your vendor register.
How we handle your data
What ProtPTX holds
- Your firm's name, entity type, contact details and billing information
- Your intake answers: staff numbers, devices, software, vendors, storage and backup practices, existing controls and physical security
- Names and roles of people in your firm, for access and training records
- The plan documents, revisions and activity log entries we produce for you
What ProtPTX does not hold
- Your clients' tax returns or source documents
- Client Social Security numbers or financial account numbers
- Any credential or login to your own systems
- Anything we would need in order to act on your behalf inside your software
The design choice behind that
The program file describes where client information lives. It does not need to contain it, so it does not. That single decision removes most of the risk a vendor in this position would otherwise create for you, and it is the first thing your IT provider should ask us about.
Our own obligations
We hold information about Massachusetts residents, which means 201 CMR 17.00 applies to us with no size threshold, the same way it applies to you. Selling security programs without maintaining one would be a poor look and a real exposure. Ours was the first one we built.
What to ask us for during diligence
These are the artifacts your program should collect from any provider in our position
This page describes our approach and the artifacts available. It is not a certification, an audit report, or a warranty. Read the contract terms, which govern.