Security & Information Handling
Security Practices Designed for CPA Firm Workflows
VSCPA follows documented security and information-handling procedures designed for its operating environment and each client relationship. Assigned client work is performed from approved VSCPA office locations using company-managed workstations. Personal devices and unapproved remote work are not permitted.
How We Protect Client Information
A Practical Security Model for Client Work
Controlled Access
Access is limited to personnel assigned to the agreed work and responsibilities.
Managed Workstations
Client work uses company-managed devices, approved software and centrally administered settings.
On-Site Operations
Assigned work is performed from VSCPA office locations under defined workplace and device procedures.
Confidentiality Procedures
Assigned personnel follow documented confidentiality and information-handling requirements.
Framework-Informed Security Practices
SOC 2 Trust Services Criteria
Selected practices are designed with reference to relevant principles involving security, availability, confidentiality and privacy.
ISO/IEC 27001
Policies and procedures are developed with reference to risk management, access control, information handling and incident management principles.
Framework references describe VSCPA's internal control design approach and do not represent certification, independent attestation, audit or endorsement.
Start the Conversation
Where Does Your Firm Need More Delivery Support?
Tell us the services, expected volume, timing and software involved. We will help define a practical starting scope.
