For CPA and Tax Firms

Every client SSN, W-2, and 1099 is in your inbox. Is anyone watching?

The IRS requires a Written Information Security Plan with continuous monitoring. The FTC Safeguards Rule made it federal law in June 2023. SentinelSMB is the monitoring component of your WISP — live in under 10 minutes, $299/month for Starter.

7-day free trial No setup fees Cancel anytime
0 $M

Tax-related identity theft losses reported to IRS Criminal Investigation in 2023

Source: IRS Criminal Investigation Annual Report
Credentialed · Insured · Operational
Licensed
ND LLC
IRS registered
EIN 41-5213020
E&O insured
$1M / $2M agg
Encrypted
AES-256-GCM
MFA required
TOTP + passkey
Audit trail
365-day retention
Threats We Actually Catch

Every attack that targets accounting firms, live-monitored.

36 detection engines sweep your Microsoft 365, Google Workspace, AWS, and Cloudflare accounts every five minutes. Critical threats surface instantly. Normal activity gets filed away.

Fraudulent return filings

Attackers phish a bookkeeper, harvest client SSNs and EFINs from email threads, and file fake returns in February. You find out when legitimate clients get rejected at the IRS.

Tax season inbox hijack

A forwarding rule added during busy season quietly copies every W-2, 1099, and engagement letter to an external inbox for three months. IRS Publication 4557 requires monitoring that catches this.

Client portal credential theft

Stolen partner credentials let an attacker log into your Drake, UltraTax, or Lacerte portal and download every prior-year return. Most firms have zero monitoring on these access events.

Why this is your problem, not your IT person’s.

Compliance Alignment

The rules and frameworks we line up to.

SentinelSMB provides the continuous-monitoring, access-control, and incident-response controls these frameworks require. Pro subscribers get the audit-ready evidence package.

IRS Publication 4557

Written Information Security Plan

Every paid tax preparer must implement a WISP that includes monitoring of access to systems holding taxpayer data. SentinelSMB provides the continuous-monitoring component and documents every access event.

FTC Safeguards Rule

Continuous monitoring mandate

Effective June 9, 2023, the FTC Safeguards Rule requires tax preparers (as financial institutions) to implement continuous monitoring, designate a qualified individual, and maintain an incident response plan.

IRS 4557, Section 4

Access control monitoring

Publication 4557 requires controlling access to taxpayer data and monitoring who accesses what. SentinelSMB tracks every login, every file access, and every permission change across Microsoft 365 and Google Workspace.

GLBA Safeguards

Customer information protection

The Gramm-Leach-Bliley Act requires financial institutions to protect customer information. SentinelSMB provides the detection and response capabilities the Safeguards Rule expects.

Questions accounting firms ask.

Does SentinelSMB make us IRS 4557 compliant on its own?

SentinelSMB provides the continuous-monitoring, access-logging, and incident-response components required by Publication 4557. You still need a written WISP document, a designated qualified individual, and employee training. Pro subscribers get six audit-ready policy templates including a WISP framework.

How does the FTC Safeguards Rule apply to my practice?

If your firm handles customer financial information — and nearly every tax and accounting firm does — you are a financial institution under GLBA and the Safeguards Rule applies. Continuous monitoring has been mandatory since June 9, 2023.

Can you help us pass the IRS e-Services suitability check?

SentinelSMB provides the access monitoring and audit trail the IRS expects to see from EFIN holders. We cannot complete the e-Services application for you, but we generate the documentation that demonstrates continuous monitoring.

What if we only use Drake or UltraTax, not Microsoft 365?

SentinelSMB monitors your Microsoft 365, Google Workspace, AWS, and Cloudflare environments — wherever your email, documents, and cloud infrastructure live. If your tax software is self-hosted with SSO against one of those, the account activity is covered.

How much does this add to a tax-season budget?

Starter is $299 a month. Pro is $599 a month. Less than ten dollars a day to monitor every client SSN, W-2, and 1099 in your system around the clock. Pro includes the Cyber Insurance Evidence Report, which most firms pay $2,000-5,000 to consultants to produce manually.

The IRS requires a WISP with monitoring. SentinelSMB is the monitoring.

Get continuous monitoring live before next tax season. 7-day free trial. Under 10 minutes to connect. Credit card required, nothing charges until day 8, cancel in one click.