Security
Written Information Security Plan
Every paid tax return preparer in the United States is required to maintain a written security plan. This is ours. It is published rather than filed away, because you are entitled to know how the information behind your return is protected.
Operated by Valim Inc. Effective date: 21 July 2025. Last reviewed: 10 September 2026.
1. Purpose and scope
This Written Information Security Plan exists to ensure the security, confidentiality and integrity of client tax data; to protect against anticipated threats to that data; and to protect against unauthorised access to or use of it that could result in harm or inconvenience to a client.
It applies to all data, systems, personnel and contractors associated with Valim's tax preparation, filing and advisory services, including the client portal at app.valim.tax and the internal systems our CPAs use to prepare returns.
The plan is designed to comply with the Gramm-Leach-Bliley Act Safeguards Rule, which applies to Valim because a paid tax return preparer is a financial institution under that rule, and with IRS Publication 4557, Safeguarding Taxpayer Data. It also takes account of the Federal Trade Commission's Safeguards Rule amendments and applicable state data protection laws.
2. WISP Coordinator
As the GLBA Safeguards Rule requires, Valim designates a single qualified individual responsible for developing, implementing, maintaining and monitoring this plan.
3. Data governance
3.1 What we classify as most sensitive
All taxpayer-provided documents, extracted data, prepared returns, workpapers and correspondence are treated as the highest sensitivity class. This includes Social Security Numbers and ITINs, dates of birth, addresses, dependants, bank details, and income and asset information for clients and their families.
3.2 Ownership
Clients retain ownership of the documents and information they provide. Valim holds and processes that information to deliver the engagement and to meet the record retention obligations that federal law places on a preparer.
3.3 Data minimisation
We collect what a return or an advisory question genuinely requires and no more. Where a document contains more than we need, we work from the parts that are relevant to the engagement.
3.4 Artificial intelligence
It is the strict policy of Valim that no client data, metadata or derived data is ever used to train or fine-tune any artificial intelligence model, whether operated by Valim or by a third party. Automated processing is performed inside Valim's controlled environment, and every return is reviewed and signed by a licensed US CPA before filing.
4. Risk assessment
The Coordinator conducts a formal written risk assessment at least annually, and additionally whenever there is a significant change to Valim's infrastructure, technology, service offering or personnel.
5. Safeguards
5.1 Encryption
5.2 Infrastructure
5.3 Access control
5.4 Network and endpoint security
5.5 Backup and continuity
6. Personnel and training
Everyone with access to client data is subject to background screening appropriate to the role, signs confidentiality obligations, and completes security awareness training on joining and at least annually thereafter. Training covers phishing and business email compromise, safe handling of taxpayer data, and how to report a suspected incident.
Access is provisioned on the Coordinator's authorisation and removed promptly on departure.
7. Vendors and service providers
Vendors with access to client data are assessed for security before engagement, are bound by written confidentiality and security obligations, and are reviewed periodically. Vendors are given the minimum access their service requires.
8. Incident response
Valim maintains a written incident response plan. On a suspected incident: contain and isolate the affected systems; preserve evidence; assess the nature and scope of any data involved; remediate; and notify.
Where taxpayer data is or may be involved, Valim notifies affected clients, the IRS Stakeholder Liaison, the appropriate state tax agencies and attorneys general, and other authorities as federal and state breach notification law and IRS guidance for tax professionals require. Notification is made without unreasonable delay.
Every incident is followed by a written review, and the findings feed back into the risk assessment and the safeguards above.
9. Retention and disposal
Valim retains returns and supporting records for at least the period federal law requires of a preparer, and longer where an open matter, notice or examination makes it necessary. Data held beyond that is reviewed and disposed of.
Clients may request permanent deletion of data Valim is not legally required to retain. Where deletion is possible the data is cryptographically erased, and backups age out under the backup retention schedule. Hardware is securely wiped or destroyed at end of life.
10. Review of this plan
This plan is reviewed at least annually by the Coordinator, and whenever a material change to Valim's systems, services or risk profile warrants it. The review date at the top of this page reflects the last such review.
11. Contact
Security questions, or to report a suspected vulnerability or incident: hello@valim.tax, marked for the attention of the WISP Coordinator.