Contents
Ten articles. Reviewed at least annually by the designated security lead.
1. Purpose and scope
This Written Information Security Plan (WISP) documents the administrative, technical and physical safeguards used to protect taxpayer information handled by the Ascen Tax USA platform.
- Scope: all taxpayer personally identifiable information, tax return information, source documents and authentication credentials, in every environment where they are created, transmitted, stored or destroyed.
- Applies to: every employee, contractor, preparer, reviewer and administrator with access to the platform, and to every service provider processing data on our behalf.
- Authority: IRS Publication 4557, IRS Publication 5708, the Gramm-Leach-Bliley Act, and the FTC Safeguards Rule at 16 CFR Part 314.
- Objectives: protect confidentiality and integrity of taxpayer data, protect against anticipated threats, protect against unauthorised access that could result in harm, and ensure secure disposal.
2. Designated security lead
A single qualified individual is accountable for this plan and for the information security programme as a whole.
- Designated qualified individual: Mehul Shah, reachable at tax@ascentaxus.com and (816) 294-5633.
- Responsibilities: maintaining this plan, running the annual risk assessment, approving role grants, overseeing service providers, leading incident response and reporting to firm leadership.
- Firm leadership reviews the security programme, material risks and incidents at least annually.
3. Risk assessment
Risks to taxpayer information are identified in writing and re-evaluated at least annually, and after any material change to systems or business practice.
- External risks: phishing and business-email compromise, credential stuffing, malware and ransomware, exploitation of application vulnerabilities, third-party/service-provider breach.
- Internal risks: excessive privilege, mishandled documents, weak authentication, unmanaged devices, insecure disposal, departure of staff without timely access removal.
- Each identified risk is rated by likelihood and impact and mapped to a specific safeguard in section 4.
- Findings and remediation owners are tracked to closure and re-tested.
4. Technical safeguards
- Encryption at rest: Social Security and taxpayer identification numbers are encrypted with AES-256-GCM and held in a dedicated vault that is separate from ordinary application tables.
- Encryption in transit: HTTPS only, TLS 1.2 or higher, HSTS enforced, insecure requests upgraded.
- Access control: roles are stored in a dedicated table separate from user profiles, granted individually by an administrator, and enforced at the database by row-level security so a stolen session cannot read another taxpayer's records.
- Authentication: multi-factor authentication for staff accounts; taxpayer sign-in uses verified email or federated identity; passwords are never stored in recoverable form.
- Session controls: automatic sign-out after 15 minutes of inactivity with an on-screen warning, hard 8-hour session lifetime, no-store cache headers on sensitive responses.
- Document storage: uploads live in private storage; access is granted only through short-lived, signed URLs issued per request.
- Automated document reading masks SSN and EIN values before any extracted text leaves the processing step.
- Logging and monitoring: authentication events, record access, administrative actions and role changes are logged with timestamp, actor, role and IP address; anomalies raise alerts to the security lead.
- Secure development: changes are reviewed before release, dependencies are scanned, and security tests run against access-control policies.
- Backups are encrypted and restore procedures are tested.
5. Administrative safeguards and employee standards
- Background screening before any staff member is granted access to taxpayer data.
- Signed confidentiality and acceptable-use agreements, renewed annually.
- Security awareness training at hire and annually, including phishing recognition and IRS-specific fraud schemes.
- Least privilege: access is granted per role and per assignment; preparers see only the returns assigned to them.
- Access is reviewed periodically and revoked the same day a person's role ends or changes.
- Clean-desk and clear-screen expectations; taxpayer documents are never stored on personal devices or personal cloud accounts.
- IRC §7216: no disclosure or use of tax return information outside preparation and filing without separate written, revocable consent recorded per return.
6. Physical safeguards
- Workstations are full-disk encrypted, screen-locked, patched and running endpoint protection.
- Paper documents, when they exist, are stored in locked storage and cross-cut shredded when no longer required.
- Devices are wiped or destroyed with a documented record before disposal or reassignment.
- Remote work is permitted only from managed devices over a trusted network connection.
7. Service provider oversight
- Providers are selected only where they can demonstrate safeguards appropriate to taxpayer data.
- Written agreements require confidentiality, security controls, breach notification and secure return or destruction of data.
- Provider security posture is reviewed periodically, and access is limited to the minimum data necessary.
- Offshore preparation is disabled by default. Where it is enabled, it is only performed by approved preparers under a return-specific §7216 consent, with access gated and logged.
8. Incident response
The response steps below are followed for any suspected or confirmed compromise of taxpayer data.
- Detect and report: any staff member who suspects an incident reports it to the security lead immediately.
- Contain: revoke sessions, tokens and credentials, isolate affected accounts and systems, preserve logs and evidence.
- Assess: determine what data was involved, how many taxpayers are affected, and the root cause.
- Notify: the IRS Stakeholder Liaison and affected state tax agencies for preparer data theft; affected taxpayers; state attorneys general and the FTC where required, within the applicable statutory deadlines.
- Recover and review: remediate the root cause, restore service, and complete a written post-incident review with corrective actions tracked to closure.
9. Retention and disposal
- Return copies and required preparer records are retained for the period federal and state rules require, generally a minimum of three years from the filing or due date, and six years where the preparer record-keeping rules apply.
- Access audit logs are retained for at least one year.
- Data that is no longer required for a legitimate business or legal purpose is securely deleted; encrypted vault records are destroyed with the associated return.
- Backups age out on their normal expiration cycle after deletion from active storage.
10. Testing, review and version control
- This plan is reviewed at least annually and after any material change to systems, staffing or business practice.
- Controls are tested through access-control tests, dependency and vulnerability scanning, and a periodic independent penetration test.
- The security lead records the review date, the changes made and the approver.
- Staff are notified of material changes and re-acknowledge the plan at their annual training.
Acknowledgement
Questions about this plan, or requests for the signed internal copy, go to Mehul Shah at tax@ascentaxus.com. See also our Trust & Compliance Center and Security & Privacy page.