The one-time custom build
What Your Firm-Specific WISP Includes
This is not template generation. The setup documents your firm's actual devices, staff, software, vendors and data practices, and maps them to the structure a Written Information Security Plan is expected to have.
The ten parts of your plan
Each one is completed with your firm's own answers, not left as a blank to fill in later.
Plan structure
Designed around IRS and FTC expectations, including IRS Publications 4557 and 5708 and the FTC Safeguards Rule
How the build runs
From intake to a plan that describes your firm
Structured intake, under ten minutes
Firm and entity type, staff numbers, devices, remote or hybrid arrangements, the software you run, vendors with access, storage and backup practices, existing controls and policies, physical office security, and your designated coordinators.
We document your real environment
Your answers become the inventory, the risk assessment and the access-control policies. Where you already have controls in place, the plan records them as they are rather than prescribing something you do not use.
Gaps become recommendations
Where an expected element is missing, the plan says so and sets out what would address it. Often that is a setting in software you already pay for.
Delivery and implementation
You receive the plan with its implementation clause, effective date and annual review schedule, ready for signature, along with the supporting policies and records.
The monthly service begins
From that date the plan is maintained rather than filed. See what that involves below.
After setup
Compliance Does Not End at Setup
A plan is only useful while it still describes your firm. Here is the specific work the monthly subscription performs, month by month.
Regulatory and guidance monitoring
We watch for changes to the FTC Safeguards Rule, IRS guidance including Publications 4557 and 5708, and related requirements, and tell you when something affects your plan.
Monthly compliance check-ins
A scheduled check each month that asks what changed in your firm and records the answer, so nothing accumulates unnoticed until renewal season.
Change prompts
When you add employees, contractors, devices, cloud tools, vendors, offices or remote-work arrangements, we prompt the plan updates those changes require.
Annual review scheduling
The annual review is scheduled and reminded rather than remembered, and it produces a dated record when it is done.
WISP revision prompts
When business conditions change enough to affect the plan, we prompt the revision and keep the previous version in the history.
Training records
Reminders when training is due, and organisation of the completion records so they can be produced on request.
Service-provider oversight tracking
Your vendor list kept current, with the diligence and contract position recorded against each one.
Compliance activity log and audit trail
A maintained, dated record of the reviews, updates, training and checks performed, which is what being audit-ready actually consists of.
Documents and history, always available
Ongoing access to your current plan documents and the full update history, so you can show not just what the plan says but when it changed and why.
Know another firm in the same position?
Most people who buy this can name three peers who signed the same attestation and quietly know their plan is out of date. Every one of them that signs up with your code takes 20% off your own renewal, and at 5 your subscription costs you nothing.
per confirmed referral
subscription is free
no payout to chase
What this service does and does not do
What ProtPTX does
- Builds a Written Information Security Plan specific to your firm
- Documents your devices, staff, software, vendors and data practices
- Monitors for relevant regulatory and guidance changes
- Prompts the updates your changes require
- Maintains a dated compliance activity log
- Helps keep your documentation current and your firm audit-ready
What ProtPTX does not do
- Guarantee legal compliance
- Prevent breaches or act as a security product
- Provide legal advice, or act as your law firm
- File anything with the IRS or the FTC on your behalf
- Replace your IT provider, your attorney or your own judgment
- Determine what the law requires of your specific firm
Requirements are not identical for every firm. What applies to yours depends on its size, services and circumstances. Where that matters, talk to your own attorney.
Start with the free readiness check
Nine questions, an instant gap analysis, and a report you can download or have sent to you with recommended next steps.