Kompflow WISP. Start today.

One purchase. Your WISP.
Done in under an hour.

A guided wizard interviews your firm in plain language, then generates a Written Information Security Plan tailored to your tax software, your team, and your state. Aligned with FTC Safeguards (16 CFR 314) and IRS Publication 4557.

Kompflow WISP
$499first year
then $99/year, cancel anytime
  • Under an hour from wizard start to downloadable WISP
  • 30-day money-back guarantee, refund window closes on first download
  • Auto-updated when regulations or your firm changes
Sample pages from a Kompflow-generated WISP
page 3Kompflow WISP
§ 1. Program Scope and Purpose

This plan documents the administrative, technical, and physical safeguards Smith & Co. CPAs maintains to protect customer information under the FTC Safeguards Rule (16 CFR 314).

FTC 314 . IRS 4557current
page 7Kompflow WISP
§ 4. Data Inventory and Classification

Taxpayer data classified as Restricted. Stored in Drake Tax, OneDrive (firm tenant), and physical client files. Off-firm access requires VPN and MFA.

FTC 314 . IRS 4557current
page 14Kompflow WISP
§ 7. Incident Response Procedures

Within 1 hour of detection, the Qualified Individual notifies the response team. Affected client notification within 30 days per state breach laws.

FTC 314 . IRS 4557current

Eleven sections total. Generated from your wizard answers.

What is inside your WISP

Every section a regulator expects.
None of the boilerplate.

The wizard produces a complete document with these sections, tailored to what your firm actually does. Nothing copy-pasted from someone else's firm.

1

Program scope and purpose

What the plan covers, who owns it, when it was last reviewed.

2

Risk assessment summary

What data you handle, what could go wrong, where your gaps are.

3

Data inventory and classification

Where taxpayer data lives, who can reach it, how it is classified.

4

Access controls

Who can access what, multi-factor authentication, account lifecycle.

5

Encryption standards

Data in transit and at rest, including your tax software and email.

6

Monitoring and logging

What activity gets logged, how long it is retained, who reviews it.

7

Incident response procedures

What you do if something goes wrong. Contacts, timelines, escalation.

8

Vendor and service provider management

Your tax software, your MSP, your email host. Each one accounted for.

9

Employee training and awareness

What your team learns, how often, and how you keep the records.

10

Disposal of customer information

How taxpayer data leaves your firm at end of retention.

11

State breach notification context

The specific notification timelines for every state your clients live in.

12

Annual review schedule

When the WISP gets reaffirmed, by whom, and what triggers a refresh.

Each section is generated from your wizard answers, then kept current by Kompflow when regulations or your firm change. Your insurer, the IRS, or your client gets the same document, current.

How it works

Three steps.
No templates. No jargon.

Plain-language wizard, generated WISP, automatic updates over time.

Step 1

Answer the wizard

A short guided interview about your firm: what data you handle, who can access it, which software you use, how your team works. Plain language, no compliance jargon.

Step 2

Get your WISP

Kompflow generates your Written Information Security Plan, tailored to what you told us. Aligned with IRS Publication 4557 and the FTC Safeguards Rule. Downloadable PDF, ready for your insurer, the IRS, or your clients.

Step 3

Stays current automatically

When regulations change or your firm changes (added staff, new systems, new vendors), Kompflow updates your stored WISP. Annual review reminder when it is time to reaffirm.

Who Kompflow WISP is for

Firms that need a working WISP without committing to a full compliance platform.

Solo and small firm CPAs

You handle taxpayer data, your insurer is asking for documentation, and you need a defensible WISP without paying a consultant $5,000.

Firms responding to IRS PTIN attestation

The IRS asks tax preparers to attest to having a written security plan. Kompflow WISP gives you a real one, not a template.

Firms applying for or renewing cyber insurance

Carriers want documented policies, risk-aware controls, and proof of an active security program. Your Kompflow WISP gives you the paper trail they ask for.

Firms answering client security questionnaires

When a tax client asks how you protect their data, point them at your WISP. It is the answer to most of their questions.

What you get for $499

Guided wizard that asks about your firm and produces your WISP
WISP covers IRS Publication 4557 and FTC Safeguards Rule requirements
Downloadable PDF you can keep forever
Secure storage of your WISP in your Kompflow account
Annual review reminder so you stay attestation-ready
Policy updates when state or federal regulations change
Automatic updates applied to your stored WISP when your firm changes (added staff, new systems, etc.)
Version history so you can show how your program has evolved

Kompflow WISP

One purchase. Your WISP. A platform that keeps it current.

$499first year
then $99/year

$499 today covers your first year, including the wizard, your WISP, secure storage, annual review reminder, and automatic policy and firm updates.

Starting in year 2, $99/year keeps your WISP current. Cancel anytime.

30-day money-back guaranteeSecured by Stripe

Refund and cancellation policy

30-day money-back guarantee

If you decide Kompflow WISP is not for you within 30 days of purchase and you have not downloaded any version of your WISP, we will issue a full refund. Refund requests are submitted via email to our support address. They are processed manually.

Refund window closes on first download

Refund eligibility ends the moment you download any version of your WISP, including drafts. Any download closes the refund window. We do this because once you have the document, the work is delivered.

Cancel anytime

You can cancel your Kompflow WISP account at any time. On cancellation, you have 15 days to export your WISP and any related data. After the 15-day export window, the account and all stored data are permanently deleted.

Reactivation

If you previously cancelled and want to use Kompflow again, the $499 first-year fee applies again. There is no partial reinstatement.

What you will see on your statement

Your $499 at checkout is billed as two line items at the same time. Both appear on your card statement and your Stripe receipt.

Today, at checkout
  • One-time setup fee$400
  • First year of $99/year maintenance$99
  • Total charged$499
Year 2 and after
  • $99/year maintenance renews on your billing date$99

The setup fee is one-time. It does not renew.

Ready when you are

Ready to get your WISP?

Under an hour from now you can have a complete, defensible Written Information Security Plan.

Need ongoing compliance management instead? See Kompflow Starter and Professional

We use cookies to measure site performance and improve your experience. No data is sold to third parties. Privacy Policy