FirmProof

For CPA and accounting firms

Your clients are already asking.

A cyber insurance renewal asks whether the business enforces multifactor authentication. A larger customer sends a security questionnaire before it signs. A contract calls for written security policies. Many firms describe the same pattern: the client brings these questions to the advisor it already trusts, and that advisor is the accounting firm.

Start with your own firm

Run your own written information security plan first.

The IRS reminded tax and accounting professionals in August 2026 that a written information security plan is a legal requirement (IRS, IR-2026-92). Under the FTC Safeguards Rule, the plan designates a coordinator, assesses risk, and puts safeguards in place that are monitored and tested.

Many design partners will start by running their own firm through FirmProof, before any client is involved. Your team learns the workflow on your own controls, and no client data enters the platform.

Planned A FirmProof control set for a written information security plan and the FTC Safeguards Rule is planned. Today the working control set is SOC 2 CC6.1, logical access security, which overlaps with the access controls a plan has to cover.

What your firm can sell

Turn client cyber questions into defined advisory engagements.

01

Cyber and compliance readiness

Assess controls, collect evidence, surface gaps, and keep the client’s readiness picture current.

02

Continuous assurance

Keep evidence and control status current through the year, so renewals, customer questionnaires and audits start from a record instead of a scramble.

03

Framework and customer readiness

Prepare clients for SOC 2 and customer security requirements without an internal GRC team. HIPAA, PCI DSS and CMMC are planned.

Your firm owns the relationship and the engagement. FirmProof supplies the operating infrastructure underneath it. See how the platform works.

Who does the work

Your team delivers. The platform carries the record.

Who does the work?
Your team runs assessment, evidence review and client delivery in FirmProof. Technical remediation stays with the client’s IT provider or a security specialist.
What does it cost your team in time?
We are measuring this with design partners and will publish what we learn.
What do you charge?
Your firm sets its own fees. We are building pricing guidance with the design partner cohort.

Independence and attest clients

Built for firms that also perform attest work.

If your firm also performs attest work for a client, AICPA independence rules apply to any nonattest service you provide to that client. Among other safeguards, client management must assume all management responsibilities for the service and oversee it through a designated individual with suitable skill, knowledge or experience (AICPA, ET 1.295.040).

FirmProof is built to support that separation. Today, every deliverable carries a named approver and a full audit record. We are designing a client acceptance step so the client’s designated individual formally accepts each policy, with both steps on the record.

Professional liability belongs in the same conversation. Before your firm offers cybersecurity advisory work, confirm with your carrier how the work fits your coverage and engagement terms.

This section is general information and is not legal or ethics advice. Each firm evaluates independence, management responsibilities and engagement terms under the standards that apply to it.

Shape the platform with us.

Design partner firms work with the founder for 90 days, starting with their own firm or a small number of clients.

Apply for the design partner cohortBook an intro call