Security

Written Information Security Plan

Every paid tax return preparer in the United States is required to maintain a written security plan. This is ours. It is published rather than filed away, because you are entitled to know how the information behind your return is protected.

Operated by Valim Inc. Effective date: 21 July 2025. Last reviewed: 10 September 2026.

1. Purpose and scope

This Written Information Security Plan exists to ensure the security, confidentiality and integrity of client tax data; to protect against anticipated threats to that data; and to protect against unauthorised access to or use of it that could result in harm or inconvenience to a client.

It applies to all data, systems, personnel and contractors associated with Valim's tax preparation, filing and advisory services, including the client portal at app.valim.tax and the internal systems our CPAs use to prepare returns.

The plan is designed to comply with the Gramm-Leach-Bliley Act Safeguards Rule, which applies to Valim because a paid tax return preparer is a financial institution under that rule, and with IRS Publication 4557, Safeguarding Taxpayer Data. It also takes account of the Federal Trade Commission's Safeguards Rule amendments and applicable state data protection laws.

2. WISP Coordinator

As the GLBA Safeguards Rule requires, Valim designates a single qualified individual responsible for developing, implementing, maintaining and monitoring this plan.

  • Coordinator: Kora Rohan, Chief Executive Officer.
  • The Coordinator owns the annual risk assessment, the incident response plan, vendor security review, and the security training programme.
  • The Coordinator reports on the state of the programme to Valim leadership at least annually.
  • 3. Data governance

    3.1 What we classify as most sensitive

    All taxpayer-provided documents, extracted data, prepared returns, workpapers and correspondence are treated as the highest sensitivity class. This includes Social Security Numbers and ITINs, dates of birth, addresses, dependants, bank details, and income and asset information for clients and their families.

    3.2 Ownership

    Clients retain ownership of the documents and information they provide. Valim holds and processes that information to deliver the engagement and to meet the record retention obligations that federal law places on a preparer.

    3.3 Data minimisation

    We collect what a return or an advisory question genuinely requires and no more. Where a document contains more than we need, we work from the parts that are relevant to the engagement.

    3.4 Artificial intelligence

    It is the strict policy of Valim that no client data, metadata or derived data is ever used to train or fine-tune any artificial intelligence model, whether operated by Valim or by a third party. Automated processing is performed inside Valim's controlled environment, and every return is reviewed and signed by a licensed US CPA before filing.

    4. Risk assessment

    The Coordinator conducts a formal written risk assessment at least annually, and additionally whenever there is a significant change to Valim's infrastructure, technology, service offering or personnel.

  • Risk identification: unauthorised access, credential compromise, data exfiltration, ransomware, insider misuse, vendor compromise, phishing and business email compromise, and system failure or data loss.
  • Risk evaluation: the likelihood and the potential impact of each identified risk on the confidentiality, integrity and availability of client data.
  • Control implementation: designing, implementing and testing the safeguards in section 5 against each evaluated risk.
  • Documentation: the assessment, the decisions taken, and the residual risk accepted are recorded in writing and retained.
  • 5. Safeguards

    5.1 Encryption

  • In transit: all data moving between a client, the portal and Valim's internal systems is encrypted using TLS. Client documents are transferred through the portal rather than by email.
  • At rest: all client tax data is protected with AES-256 encryption. Encryption keys are managed in a dedicated key management service, separately from the data they protect.
  • 5.2 Infrastructure

  • Production data and systems are hosted in a private, logically isolated cloud environment located within the contiguous United States.
  • Environments are segregated. Production data is not copied into development or test environments.
  • 5.3 Access control

  • Least privilege: internal access to production systems and client data is restricted to named, authorised personnel whose role requires it, and is granted for the narrowest scope that allows the work to be done.
  • Multi-factor authentication is required for access to systems holding client data, in line with the Safeguards Rule.
  • Passwords must meet complexity requirements and are stored hashed and salted. Shared accounts are not permitted.
  • Access is reviewed periodically, and is revoked promptly when a person changes role or leaves.
  • Access to client data is logged, and logs are retained and monitored.
  • 5.4 Network and endpoint security

  • Systems are protected by firewalls and network controls that restrict inbound access to what is required.
  • Devices used to access client data are managed, encrypted at the disk level, and require screen lock and current security patches.
  • Software and dependencies are kept current, and security patches are applied on a defined schedule.
  • 5.5 Backup and continuity

  • Client data is backed up, backups are encrypted, and restoration is tested so that a failure or ransomware event does not become a loss of client records.
  • 6. Personnel and training

    Everyone with access to client data is subject to background screening appropriate to the role, signs confidentiality obligations, and completes security awareness training on joining and at least annually thereafter. Training covers phishing and business email compromise, safe handling of taxpayer data, and how to report a suspected incident.

    Access is provisioned on the Coordinator's authorisation and removed promptly on departure.

    7. Vendors and service providers

    Vendors with access to client data are assessed for security before engagement, are bound by written confidentiality and security obligations, and are reviewed periodically. Vendors are given the minimum access their service requires.

    8. Incident response

    Valim maintains a written incident response plan. On a suspected incident: contain and isolate the affected systems; preserve evidence; assess the nature and scope of any data involved; remediate; and notify.

    Where taxpayer data is or may be involved, Valim notifies affected clients, the IRS Stakeholder Liaison, the appropriate state tax agencies and attorneys general, and other authorities as federal and state breach notification law and IRS guidance for tax professionals require. Notification is made without unreasonable delay.

    Every incident is followed by a written review, and the findings feed back into the risk assessment and the safeguards above.

    9. Retention and disposal

    Valim retains returns and supporting records for at least the period federal law requires of a preparer, and longer where an open matter, notice or examination makes it necessary. Data held beyond that is reviewed and disposed of.

    Clients may request permanent deletion of data Valim is not legally required to retain. Where deletion is possible the data is cryptographically erased, and backups age out under the backup retention schedule. Hardware is securely wiped or destroyed at end of life.

    10. Review of this plan

    This plan is reviewed at least annually by the Coordinator, and whenever a material change to Valim's systems, services or risk profile warrants it. The review date at the top of this page reflects the last such review.

    11. Contact

    Security questions, or to report a suspected vulnerability or incident: hello@valim.tax, marked for the attention of the WISP Coordinator.