PTIN renewal season is here. Make sure your WISP documentation is current before you complete your renewal attestation.

Check your readiness
Home Security

Our security program

We are a service provider. You are required to check on us.

16 CFR 314.4(f) and 201 CMR 17.03(2)(f) both require you to select service providers capable of maintaining appropriate safeguards and to impose those safeguards by contract. That includes us. This page exists so you can do that diligence properly, and so it can go straight into your vendor register.

How we handle your data

What ProtPTX holds

  • Your firm's name, entity type, contact details and billing information
  • Your intake answers: staff numbers, devices, software, vendors, storage and backup practices, existing controls and physical security
  • Names and roles of people in your firm, for access and training records
  • The plan documents, revisions and activity log entries we produce for you

What ProtPTX does not hold

  • Your clients' tax returns or source documents
  • Client Social Security numbers or financial account numbers
  • Any credential or login to your own systems
  • Anything we would need in order to act on your behalf inside your software

The design choice behind that

The program file describes where client information lives. It does not need to contain it, so it does not. That single decision removes most of the risk a vendor in this position would otherwise create for you, and it is the first thing your IT provider should ask us about.

Our own obligations

We hold information about Massachusetts residents, which means 201 CMR 17.00 applies to us with no size threshold, the same way it applies to you. Selling security programs without maintaining one would be a poor look and a real exposure. Ours was the first one we built.

What to ask us for during diligence

These are the artifacts your program should collect from any provider in our position

01Our written information security programSummary form, available on request.
02A safeguards clause for your contractPre-drafted to satisfy 314.4(f) and 17.03(2)(f). Arrive with it and the negotiation is over before it starts.
03Our subprocessor listWho we rely on, and for what.
04Our incident notification commitmentWhat we tell you, and how quickly.
05Data return and deletion termsWhat you get back when you leave, and what we delete.

This page describes our approach and the artifacts available. It is not a certification, an audit report, or a warranty. Read the contract terms, which govern.