Security & privacy

Layered protection for sensitive financial data.

Strong security is not one product or one promise. It combines protected endpoints, secure systems, limited access, written controls, trained people, backups, and a clear response plan.

CLIENT DATALAYERED PROTECTION
Our approach

What protects client information?

Aouad Associates uses a layered program that includes SentinelOne endpoint protection, designated encrypted client-data workflows, multifactor authentication, role-based access, backup and response planning, staff safeguards, and a Written Information Security Plan aligned with IRS Publication 4557, IRS Publication 5708, and the FTC Safeguards Rule.

Defense in depth

Eight connected safeguards.

Each layer supports the others. Endpoint protection does not replace access control; encryption does not replace staff awareness; and a written plan does not replace ongoing review.

Protect

SentinelOne endpoint security

Endpoint protection powered by AI and response capabilities support immediate threat detection, containment, investigation, and recovery on protected devices.

Encrypt

Protected workflows for client data

Sensitive records are exchanged through designated encrypted channels. Encryption in transit and at rest is used where supported by the approved system; ordinary email is not treated as a secure document portal.

Verify

Multifactor authentication

Multifactor authentication adds a second verification step to supported systems that hold or access sensitive client information.

Limit

Limited access

Access is assigned by role and business need, reviewed as responsibilities change, and removed when it is no longer required.

Plan

Written Information Security Plan

The security program is documented through a WISP aligned with the IRS security plan framework and the FTC Safeguards Rule.

Recover

Backup and response planning

Backup practices, recovery procedures, and an incident response process help the firm prepare for service disruption, data loss, or suspected theft.

Train

People and phishing safeguards

Team responsibilities, access habits, phishing awareness, secure file handling, and escalation expectations are part of the control environment.

Review

Vendor and control review

Security depends on the full workflow, so service providers, access, systems, and written controls are reviewed as the practice and threat environment change.

Encryption, stated clearly

Use the secure channel for sensitive records.

Social Security numbers, tax returns, payroll records, banking details, identity documents, and other sensitive files should be exchanged only through the designated secure client workflow.

Transport encryption protects data moving between approved systems; at-rest encryption protects stored data where supported. “End-to-end encryption” is used only when the selected platform and workflow technically provide it from sender to authorized recipient.

Use

  • The designated secure client portal
  • Multifactor authentication
  • Unique passwords or a password manager
  • Verified recipient and upload instructions

Avoid

  • Ordinary email attachments with sensitive data
  • Reused or shared passwords
  • Unverified links or unexpected upload requests
  • Sending credentials or security codes by email
Official security framework

IRS and FTC guidance behind the program.

IRS Publication 4557 helps tax professionals safeguard taxpayer data and understand the FTC Safeguards Rule. IRS Publication 5708 provides a framework for a Written Information Security Plan.

Important security note

No security program can guarantee that every threat will be prevented. This page describes a layered approach and program alignment; it is not an IRS certification, an independent security attestation, or a warranty of absolute security. Specific technologies and controls may change as risks and systems evolve.

Ask a security question →