Home/Security Measures

Security
Measures

How we protect your information across our client portal and secure file transfer systems.

Security measures

Protecting your information

CCG Certified Public Accountants takes the security of client information seriously. Because our work involves sensitive financial, tax, and personal data, we've built our client-facing systems around industry-standard security practices designed to keep that information safe at every step.

This page describes, in general terms, the measures we use. We don't publish exhaustive technical detail about our infrastructure, since doing so could itself create risk — but we want every client to understand the care we take.

Secure client portal

Our client portal is the primary way we exchange documents, statements, and returns with clients. Access to the portal requires individual login credentials, and data transmitted to and from the portal is encrypted in transit using industry-standard encryption protocols.

Encryption in transit

Whenever documents are uploaded or downloaded through our secure systems, the connection between your device and our servers is encrypted, helping prevent interception of your information while it's being transmitted.

Access controls

Access to client files and portal accounts is limited to authorized personnel who need that information to perform their work. Login credentials are unique to each user, and we encourage clients to choose strong, unique passwords and to avoid sharing portal credentials with anyone.

Ongoing diligence

We regularly review and update our internal practices to reflect current industry-standard security expectations. Our goal is to apply reasonable, up-to-date safeguards to every system that touches client data — while recognizing that no system can guarantee absolute security.

The layers behind that diligence

"Industry-standard security" isn't one thing — it's a stack of specific safeguards working together. Here's what makes up that stack for the systems we use to exchange documents with clients:

  • SSAE 16/SAS 70 Type II certified datacenter — Servers are hosted in a facility independently audited to SSAE 16/SAS 70 Type II standards, the same certification the Sarbanes-Oxley Act requires of publicly traded companies, with 24/7 guarded, video-monitored access and dual-factor biometric entry controls for datacenter personnel.
  • Encrypted file storage — Files are encrypted not only while in transit, but while they sit on the server — which is where they spend nearly all of their time.
  • Filename obfuscation — Stored files are renamed to random strings of characters, so they can't be identified by filename alone even in the unlikely event a server were compromised.
  • Forced SSL transfer — Any attempt to move data insecurely is automatically redirected to an encrypted connection.
  • SQL injection protection — Our systems use parameterized database queries, the standard defense against SQL injection attacks.
  • Login attempt limits — After a handful of failed login attempts, a CAPTCHA challenge kicks in to block automated password-guessing.
  • Configurable password strength — Weak passwords are rejected outright, and administrators can require stronger password policies firm-wide.
  • Firewall protection — A dedicated firewall is configured with a minimal number of open ports and IP-based access restrictions.
  • Hourly virus scanning — Servers are scanned continuously, with virus definitions updated every hour.
  • Encrypted, cross-server backups — Backup files are encrypted and stored separately from the originals, so a compromised backup alone can't expose client data.
  • Denial-of-service protection — Traffic patterns typical of denial-of-service attacks are detected and automatically blocked before they can overwhelm the servers.
  • Intrusion prevention — Every incoming data packet is inspected in real time to determine whether it's legitimate before it reaches the servers.
  • Detailed audit trails — Every transaction is logged, supporting compliance with the Gramm-Leach-Bliley Act and giving us a verifiable record if we ever need to confirm information wasn't accessed improperly.
  • OS hardening and patch management — Server operating systems are continually patched and hardened to close off newly discovered vulnerabilities.

Your role in staying secure

Security is a shared responsibility. We recommend clients avoid sending sensitive documents by unencrypted email, use the client portal whenever possible, keep devices and browsers up to date, and contact us right away if you ever suspect unauthorized access to your account.

Trust is earned through consistent, careful handling of the information you share with us.

Questions about our security practices?

If you have questions about how we handle or protect your information, reach out to our team directly — we're happy to talk through it.

Ready when you are

Let's make the numbers
work for you.

Book a complimentary consultation and discover what it feels like to have finances handled — precisely, proactively, and personally.