Security Designed Around Taxpayer Data

Accounting firms hold exactly what attackers want: Social Security numbers, financial records and identity data. Here is — in plain language — how a MangoCloud environment is protected, and where your firm’s responsibilities and ours meet.
Service

Layered Technical Controls

Identity and Access

  • Multi-factor authentication for all user sessions
  • Role-based access aligned to firm responsibilities
  • Rapid account disablement for departures
  • Session encryption in transit

Data Protection

  • Automated backups with encryption at rest and in transit
  • Offsite and immutable copy options
  • Defined retention schedules
  • Periodic restore testing

Infrastructure

  • US-based data center infrastructure
  • Hardened, patched Windows environments
  • Network segmentation between customers
  • Coordinated, announced maintenance windows

Threat Protection

  • Endpoint detection and response on hosted servers
  • 24/7 monitoring and alerting
  • Email and web filtering options
  • Documented incident response procedures

01.

FTC Safeguards Rule

Tax preparers and many accounting firms are ‘financial institutions’ under the GLBA Safeguards Rule, required to maintain a written information security program with specific technical controls. Our environment provides several of those controls — MFA, encryption, monitoring, access management — as managed defaults you can reference in your program.

02.

IRS Publication 4557

The IRS’s data-safeguarding guidance for tax professionals calls for protecting taxpayer data with measures including access controls, encryption and backup. Hosting with managed security addresses many of the technical items on that checklist, with documentation to show how.

03.

Written Information Security Plan (WISP)

Every firm with a PTIN is expected to maintain a WISP. We provide environment documentation — controls, backup schedules, access procedures — that your firm can incorporate into its plan.
MangoCloud provides technology controls and documentation that support customer compliance programs. Regulatory compliance remains each firm’s responsibility, and requirements vary by firm and jurisdiction. Nothing on this page is legal advice — consult your compliance advisor for your firm’s specific obligations.

Shared Responsibility Model

MangoCloud Is Responsible For

  • Operating and securing the hosted infrastructure
  • Applying OS patches and platform updates
  • Running, encrypting and monitoring backups
  • Enforcing MFA and managing platform access controls
  • Monitoring for and responding to platform-level threats
  • Providing documentation of environment controls

Your Firm Remains Responsible For

  • Maintaining your firm’s WISP and overall compliance program
  • Managing software licenses and vendor agreements
  • Deciding who at your firm gets access to what
  • Training staff on phishing and safe data handling
  • Meeting professional and regulatory obligations to clients
  • Reviewing and approving user access periodically
FAQs

Yes. Customer environments and backups run on US-based infrastructure. If your firm has specific data residency requirements, raise them during assessment and we'll document how they're met.

No provider can make your firm compliant by itself — compliance programs include policies, training and processes only your firm controls. What we provide are managed technical controls (MFA, encryption, monitoring, backup) that support and simplify your program, plus documentation you can reference in it.

Environments are logically separated with access controls and network segmentation, and dedicated (fully isolated) environments are available for firms that require them. The right model for your firm is confirmed during assessment.

We operate documented incident response procedures: detection and alerting, containment, investigation, remediation and customer communication. Affected customers are notified with facts and actions — not silence.

Yes. We regularly help customers answer technical questions on cyber-insurance applications and client security questionnaires by documenting the controls in place in their hosted environment.

No, and you should be skeptical of anyone who does. Layered controls substantially reduce risk, and monitoring shortens response time — but security is ongoing risk management, not a one-time guarantee. We'd rather be honest about that and show you the controls.

Talk Expert

Ask Us the Hard Security Questions

Bring your security questionnaire, your WISP checklist or your insurer’s application. We’ll walk through exactly which controls our environment provides.