How it works
Answer once. Stay current every month.
ProtPTX is built in three layers. First we write down how your firm actually handles client information. Then we keep that description true on the schedule the regulations set. Then, once the map exists, we start taking work off your desk.
Layer one
The intake: from questions to a real document
A structured interview, not a blank template. Roughly twenty minutes for a solo practice, longer for a firm with several offices or an outsourced team.
The firm
Entity, practice type, headcount, locations, remote and offshore staff, who holds a PTIN, who is designated as the individual responsible for the program.
The systems
Tax and accounting software, document storage, email, portal, backup, endpoint protection, password manager, multi-factor coverage, devices that leave the office.
The data
Which categories of client information you hold, where each one lives, how long you keep it, how it is transmitted, and how it is destroyed.
The vendors
Every third party that stores, processes, or can reach client information, including the ones nobody thinks of: the shredding service, the bookkeeper, the IT contractor.
The people
Access levels, onboarding and offboarding steps, confidentiality agreements, the disciplinary measure for a violation, and when training last happened.
The AI question
Which assistants are already in the building, who is using them, and on what. Most firms discover something here they did not know about.
Where the answers go
Every answer is stored as a structured field, not as prose. That is what lets the same answer feed your program document, your data inventory, your vendor register, and your annual review without you typing it four times. Change the answer once and every artifact that depends on it is reissued with a new version number and a date.
Layer one, output
Configurable documentation, cited clause by clause
Not a PDF with your name in the header. A set of versioned, dated documents that describe your firm, each clause carrying the provision it satisfies.
Written information security program
Structured to the seven-section framework in IRS Publication 5708 and mapped against the FTC Safeguards Rule element by element.
IRS Pub. 570816 CFR 314.4Incident response plan
Roles, escalation, containment, the documentation duty, and who makes the notification call. Written before you need it, not during.
16 CFR 314.4(h)201 CMR 17.03(2)(j)AI use policy
Which tools are approved, what may never be pasted into one, who reviews output, and how use is logged. Your firm's rules, written down.
See the moduleData inventory and retention schedule
What you hold, where it sits, how long it stays, and how it is destroyed when the period ends.
16 CFR 314.4(c)(6)M.G.L. c. 93IVendor register and contract clauses
Every service provider, what it touches, what diligence you did, and the safeguards clause your contract needs to carry.
16 CFR 314.4(f)201 CMR 17.03(2)(f)Staff acknowledgments and training log
Rules of conduct, signed acknowledgments, and a dated completion record for every person, every cycle.
16 CFR 314.4(e)201 CMR 17.04(8)Configurable means configurable
You can edit any clause, add your own, or suppress one that does not apply to your firm. If you suppress a clause that a regulation requires, the file says so plainly and the item stays on your action list until you resolve it. The software will not quietly drop a requirement to make your document look finished.
Export to Word or PDF at any time. The documents are yours, in an open format, whether or not you stay a customer.
Layer two
The calendar the regulations already wrote
This is the part that makes a program different from a document. The obligations recur. ProtPTX puts each one on a date, prompts the work, and closes it into a dated entry.
Every month
Change and vendor review
Forward the month's software receipts and note any staff or system change. ProtPTX classifies whether each vendor touches client information, drafts the diligence record and the contract clause, updates the affected documents, and writes the change log entry.
Every month
Micro training with a completion log
A five-minute refresher on one topic, sent to each person, with a dated completion record attached to the program file. Training is an explicit duty in both the federal rule and the Massachusetts standards, and the proof is the log.
Every quarter
Access and inventory reconciliation
Confirm who still has access to what, that departed staff are fully removed, and that the device inventory matches the hardware actually in use.
Once a year
Scope review and program evaluation
The annual review required by the Massachusetts standards and the program evaluation required by the federal rule, produced as a signed, dated document rather than as a reminder you dismissed.
October to December
PTIN renewal pack
A current plan, signed and dated, with the year's record attached, ready before you answer line 11 on Form W-12. More on the renewal window
On any incident
Responsive action record
The documented incident review both regimes require, plus notification scaffolding for the FTC, for state authorities, and for affected individuals if the event is reportable. Your attorney makes the call. ProtPTX makes sure the record exists.
What you are actually buying
Twelve dated entries a year showing the firm paid attention. Continuity is the asset, and continuity cannot be bought retroactively. If you leave, you keep every document and every log we produced while you were here. Nothing is held hostage.
Know another firm that needs this? Each one that signs up with your code takes 20% off your own renewal. Five and you pay nothing.
How the discount works →Layer three
Once the map exists, the work can move
By month three, the file knows your systems, your data flows, your staff, and your vendors better than any other software you own. That is what makes the next part possible, and it is why we do not offer it on day one.
Notice triage and response drafting
Tax authority correspondence sorted, summarized, and drafted against your file, with every action logged under the supervision rules your firm already follows.
Onboarding and offboarding runbooks
The access grants, acknowledgments, training assignment, and device steps fire as a checklist the moment a person joins or leaves, and close into the record.
Insurance and due diligence packs
Cyber liability applications and client security questionnaires answered from the file instead of from memory, with the supporting evidence attached.
Client-facing security summary
A short, accurate description of how you protect client data, suitable for your engagement letter or your own website. Increasingly, clients ask.
Layer three is offered to firms already running the monthly cadence. Availability by module varies. Ask us what is live today rather than assuming from this page.
Nine questions, and you will know where you stand
The assessment runs against the elements the regulations enumerate, not against a checklist we invented. Results are shown instantly, in your browser.