WISP, risk assessment, incident response, vendor management, and continuous control testing. Tailored to your firm, kept current automatically, written so your insurer, the IRS, or your client can read it. Three tiers, starting with the WISP for $499.
Auto-updated 2 days ago
Quarterly review on file
Annual reaffirmation
14 vendors tracked
Kompflow is not a single document and not a generic GRC suite. It is the set of compliance deliverables a CPA firm actually needs, generated from your firm's answers and kept current as regulations and your firm change.
Aligned with FTC Safeguards (16 CFR 314) and IRS Pub. 4557. Tailored to your firm.
Guided. Plain language. Drives your WISP and your remediation plan.
What to fix, in what order, with prompts and explanations.
Scenario-specific playbooks: ransomware, lost device, wire fraud, breach.
Inventory, security posture, contract evidence. One place per vendor.
Answer cyber insurance questionnaires in your firm's actual posture, not boilerplate.
Team training tied to your WISP. Records kept for insurers and the IRS.
GRC-style structure, control mapping across frameworks, continuous evidence.
Each deliverable is generated from your firm's answers and kept current automatically.
No templates, no boilerplate, no copy and paste from someone else's firm.
Kompflow WISP starts today. You buy it, you get your WISP. Kompflow Starter and Kompflow Professional are in a selective rollout. We onboard each firm directly so the platform fits how you actually work.
For firms that need a working WISP for IRS PTIN attestation, cyber insurance, or basic FTC Safeguards documentation.
then $99/year
30-day money-back guarantee on Kompflow WISP.
For firms that need ongoing compliance management beyond a single document.
billed monthly
Selective rollout. We respond within 2 business days.
For growing firms that need continuous control evaluation and a framework view, not just an annual review.
billed monthly
Selective rollout. We respond within 2 business days.
Every CPA firm gets here for one of these reasons. The good news is you do not need four different deliverables. You need one current WISP that holds up to all four readers.
The IRS asks tax preparers to attest to having a written security plan. Most attest yes. Most do not have one that holds up if questioned.
Carriers want documented policies, risk-aware controls, and a current WISP. Without them the application stalls or the premium spikes.
A larger tax client asks how you protect their data. Without a WISP and a security summary you can attach, the relationship gets awkward fast.
Cross 5,000 client records and the rule changes shape: written IRP, vulnerability testing, board reporting. The work multiplies. Kompflow has a tier for that.
Most WISP products assume you comply. Kompflow asks. The difference shows up the first time an insurer or the IRS reads what you produced.
Your firm's documents describe how you protect taxpayer data.
We hold them to the same standard you would.
TLS 1.2+ in transit, AES-256 at rest. Your WISP and supporting data are not stored in plain text.
Every account is protected with multi-factor authentication.
Cancel anytime. You have 15 days to export your data. After that, it is permanently deleted.
We do not mine your WISP or sell access to your data. Your documents are yours.
Everything you need to know about Kompflow. If we missed something, ask.
Still have questions?
Contact usFor MSPs and vCISOs
Kompflow's Partner Portal gives you a cross-client dashboard, white-label reporting, team access, and a step by step process across every client at once.
Buy the WISP yourself if you need the document.
Talk to us if you want the platform.
We use cookies to measure site performance. No data is sold to third parties. You can opt out at any time. Privacy Policy