Your tax software forces MFA. Does your email?
Verified WISP checks your email and cloud accounts one by one, writes your WISP from what is actually true, and gives you dated proof for your insurer and your clients. Under an hour. No call. Nothing to install.
You check "Yes" three times a year
Every fall you renew your PTIN, and line 11 of the W-12 asks you to confirm you know paid preparers must keep a written information security plan. Yes.
You have a WISP. Maybe it is the IRS template, maybe a colleague sent you theirs, maybe your insurer had one. It says multi-factor authentication is in place. Yes.
Then your cyber or E&O renewal asks: "Do you use MFA?" Yes.
It feels true. Your tax software makes you type a code every time you log in. But nobody, including you, has actually looked at every account your firm uses.
The rule doesn't stop at your tax software
Drake, UltraTax and others now require MFA inside their own software. That is a good thing, and it is also where the confusion starts. The FTC Safeguards Rule, which applies to paid tax preparers, does not say "in your tax software". It says this:
"Implement multi-factor authentication for any individual accessing any information system, unless your Qualified Individual has approved in writing the use of reasonably equivalent or more secure access controls."16 CFR 314.4(c)(5). The small-firm exemption in 314.6 does not remove this requirement.
Any information system includes your email, where W-2s, 1099s and copies of driver's licenses arrive every season. It includes the shared drive where last year's returns sit, and the front-desk mailbox everyone uses. Your tax software can't see those accounts, so it can't protect them.
That is how many firm break-ins start: someone clicks a convincing "new client" email, enters a password, and the attacker is inside the mailbox, reading everything that comes in.
The IRS won't ask for your WISP. Your insurer will.
Most preparers figure nobody checks, and they are mostly right about the IRS. The check comes from somewhere else: the day you file a claim, your insurer compares what you said on your application with what was really in place. An account without MFA that you said had it is exactly the kind of gap that turns a claim into an argument.
- If a breach happens, IRS Publication 1345 asks e-file providers to report it no later than the next business day after confirmation.
- If it involves the information of 500 or more people, the Safeguards Rule requires notifying the FTC within 30 days of discovery.
- Serious e-file violations can lead to suspension from IRS e-file for one or two years (Publication 3112). For most firms, that is the season.
None of this means you are in trouble. It means the moment you most need proof is the moment it is hardest to produce.
Why a template can't fix this
A template describes a firm. A copied WISP describes someone else's firm. A $999 binder describes your firm on the day it was written. None of them can tell you that the seasonal preparer you added in January never set up MFA, or that anyone on the internet can send email that looks like it comes from your domain.
This is not your fault. The Safeguards Rule was written for financial institutions and handed to people who prepare 1040s. Even two FTC commissioners warned, when it was updated, that asking too much of small businesses may lead them to fail at even the basic protections.
Verified WISP: we check, instead of asking you to check a box
Three steps. Under an hour of your time, in one sitting, with no call.
Outside: your domain
We look at your firm the way an attacker or an insurer does: whether someone can send email as your domain, your certificates, and what is exposed to the internet. Nothing to install.
Inside: every accountComing soon
With read-only permission, we check your Microsoft 365 or Google Workspace settings. Not "MFA is enabled": who has it, who doesn't, and who was added since last month. We never open your email, your files or client data.
On paper, and trueComing soon
We write your WISP from what we found, following the IRS Publication 5708 structure. Every statement carries a date: verified by us, or stated by you. We re-check every month and tell you when something changes.
What one firm learned the hard way
Catharine Drake Madeley runs a CPA firm in Austin with about 200 clients. Before her breach, she thought the firm was too small to attract identity thieves. One employee received a convincing email.
"And she clicked on it, and she entered her password, and, poof, like magic, they had access to her email account."Catharine Drake Madeley, CPA, quoted in the Journal of Accountancy, June 2025. Not affiliated with Fusion AI.
From the mailbox, the attackers worked out which client portal the firm used. What saved the firm was how fast and how honestly it responded. "We didn't lose a single client in this process," she told the Journal. Knowing exactly what was in place, and being able to show it, is what makes that kind of response possible.
What you get
| What it does for you | |
|---|---|
| Account check | Who has MFA and who doesn't, on email and cloud, account by account (Microsoft 365 or Google Workspace). Coming soon. |
| Domain check | Whether your domain can be spoofed (SPF, DKIM, DMARC), your certificates, and services exposed to the internet. Available today. |
| Your WISP, written from what we found | Follows the IRS Publication 5708 structure: Qualified Individual, safeguards actually in place, incident response, annual review. Coming soon. |
| Evidence Pack | One dated PDF for your insurer or a client: your WISP plus the checks behind it. Coming soon. |
| Monthly re-check | We check again every month and email you if an account loses MFA or a new one appears without it. Coming soon. |
| MFA without lockouts | A plain guide to backup codes and second devices, so MFA never locks you out in the middle of the season. |
| The rules in plain English | What 16 CFR 314, the W-12 and Publication 1345 actually say. No scare tactics, no made-up fines. |
What we read, and what we never read
- We read: the list of accounts in your Microsoft 365 or Google Workspace, and whether each one has multi-factor authentication. Read-only.
- We read: public information about your domain, the same any visitor can see.
- We never read: your email, your files, your tax software, or any taxpayer information.
- Nothing to install on your computers. You can disconnect us at any time from your Microsoft or Google admin console.
Pricing
Simple yearly pricing. No contract beyond the year, no user minimums, no setup fee.
Solo
- Domain and account check
- Your WISP, written from what we found
- Evidence Pack
- Monthly re-check
Firm
- Everything in Solo
- Up to 20 accounts checked
- Seasonal staff tracking
- Priority email support
Early access: nothing to pay today. Join the list and we will email you when your account is ready, with the founding price locked for your first year.
Proof or your money back: if you are not satisfied within 30 days, or if we cannot check your accounts, you get a full refund.
Questions
Nobody ever checks WISPs. Why bother?
The IRS rarely asks to see one. Your insurer is different: when you file a claim, what you said on your application is compared with what was in place. Verified WISP is about being able to show that.
My tax software already makes me use MFA. Isn't that enough?
It covers your tax software. The Safeguards Rule asks for MFA on any information system, which includes your email and cloud storage. Those are the accounts we check.
Do I have to renew my PTIN with a WISP?
Line 11 of Form W-12 asks you to confirm you are aware that paid preparers must keep a written information security plan. It is not a certification, and the IRS does not collect your WISP. The legal requirement to have one comes from the FTC Safeguards Rule.
I'm a one-person office. Am I too small for this?
The WISP and MFA requirements apply regardless of size. Firms with information on fewer than 5,000 people are exempt from four specific items (such as a written risk assessment and an annual report), not from the plan itself or from MFA. The Solo plan is made for you.
I use Gmail or Outlook.com, not my own domain.
Verified WISP needs your own domain to check your accounts. Until then, we will send you a free guide to securing a personal Gmail or Outlook account, and it is a good reason to move to a professional domain.
Will MFA lock me out during the season?
Not if it is set up with backup codes and a second device. Our guide walks you through it, and nothing we do touches your tax software.
Can't I just copy a template?
You can, and many do. A template describes a generic firm. If it says MFA is everywhere and one account doesn't have it, your WISP says something that isn't true. We write yours from what we actually find.
Does this make me compliant?
No product can promise that, and we won't. Verified WISP gives you an accurate picture, a plan that matches it, and dated evidence. The decisions and the signature stay yours.
Who we are
Fusion AI is built by Fusion Security (FUSSEC Services LLC). A real person reads every message: hello@fusion-security.com.
Check the box knowing it's true
Join early access. We will email you when your account is ready, with the founding price locked in. Meanwhile, the domain check is free.
We only use your email to tell you when early access opens. Ask us to delete it anytime.